SK0-005 · domain
scenario questions
Practise CompTIA Server+ SK0-005 scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice scenario questions questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about scenario questions
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common scenario questions exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All scenario questions questions (185)
Click any question to see the full explanation, or start a practice session above.
A server administrator notices that a recently installed PCIe network card is not being recognized by the operating system. The server is running Windows Server 2019. The administrator has verified that the card is securely seated and that the slot is enabled in the BIOS. Which of the following should the administrator try FIRST to resolve the issue?
Easy2An administrator needs to configure a critical web service on a Linux server to automatically restart if it crashes unexpectedly. The server uses systemd. Which of the following best accomplishes this goal?
Medium3A server administrator receives an alert that a critical server's disk is almost full. Upon investigation, the administrator finds a large log file that has grown significantly. The log file is rotated daily, but today's rotation failed. Which command should the administrator use FIRST to free up space immediately?
Easy4A database server running on a Linux VM has started experiencing periodic crashes. The VM is hosted on an ESXi hypervisor. The system logs show entries: 'kernel: Out of memory: Kill process 12345 (mysqld) score 700 or sacrifice child'. The VM has 16GB RAM allocated and no memory overcommitment on the host. The DBA reports that the database workload hasn't increased. Which of the following actions should be taken FIRST to diagnose the issue?
Hard5A systems administrator is configuring a new server that will host a mission-critical database. The server has two redundant power supplies. The organization's data center has two separate power circuits, each backed by a different UPS. Which of the following power configurations provides the BEST redundancy?
Medium6A virtualization administrator notices that a critical VM on an ESXi host has high CPU Ready time (%RDY) according to performance charts. The VM has 8 vCPUs assigned, and the host has two physical CPUs with 8 cores each. Other VMs on the host are performing normally. Which of the following actions would MOST likely resolve the high CPU Ready time for this VM?
Hard7A Linux server administrator notices that the /var partition is 95% full. To free space quickly, the administrator decides to delete old log files. Which of the following commands should the administrator use to find and delete log files older than 30 days in the /var/log directory?
Medium8A server has been intermittently crashing, and the system logs repeatedly show 'Machine Check Exception (MCE) errors' referencing a specific CPU core. The server is under warranty. The technician suspects a hardware fault. Which of the following actions should be taken FIRST to resolve the issue while minimizing downtime?
Hard9An organization uses a cloud-based backup solution with immutable storage to protect against ransomware. However, after a recent attack, an attacker with stolen administrator credentials was able to delete the backup data. Which of the following BEST explains why the backups were deleted?
Hard10A system administrator manages a collection of Linux web servers that store custom application configurations in /etc/app/config. The configuration changes frequently, and the admin needs to implement an automated daily backup solution that captures the directory at 1 AM, compresses it with gzip, and retains the last 5 days of backups on a central NFS-mounted backup volume /mnt/backups. The solution should be simple and use standard tools. Which approach best meets these requirements?
Medium11A server has four 1 Gbps network interface cards (NICs) configured in a Link Aggregation Control Protocol (LACP) team with a managed switch. The switch ports are confirmed to be correctly configured for LACP. However, during a file transfer test, the observed aggregate throughput is only about 2 Gbps. Which of the following should the administrator verify FIRST?
Hard12A server administrator is restoring a file server from a full backup taken 7 days ago and incremental backups taken daily. The restoration fails with an error about missing catalog files. What is the most likely cause?
Hard13Refer to the exhibit. A disaster recovery test reveals the following timeline for a critical application. The business requires an RTO of 2 hours. Which of the following actions would MOST effectively reduce the RTO to meet the requirement?
Hard14An organization requires a disaster recovery site that can be operational within 24 hours after a disaster declaration, with critical data replicated on a regular basis, but not necessarily real-time. Which type of site should they implement?
Medium15A system administrator is configuring a backup schedule for a critical database server that must be available 24/7. The company's recovery point objective (RPO) is 1 hour and recovery time objective (RTO) is 4 hours. The database files change frequently, but the operating system and application binaries rarely change. Which of the following backup strategies would BEST meet these requirements while minimizing storage and backup window impact?
Hard16A Windows Server 2019 file server hosts a shared folder named \\FS01\SalesDocs. The share permissions are configured to grant the 'Everyone' group Full Control. The NTFS permissions on the D:\Shares\SalesDocs folder are set as follows: The 'Sales' security group has Allow Read & Execute, List Folder Contents, and Read. The 'Managers' group has Allow Modify. A user, Alice, is a member of the 'Sales' group and also a member of the 'Temporary_Contractors' group. She recently had her account moved from the 'Contractors' OU to the 'Sales' OU. When Alice attempts to access \\FS01\SalesDocs from her Windows 10 workstation, she receives an 'Access Denied' error. Other members of the 'Sales' group can access the folder without issues. The administrator verifies that Alice's group membership includes both 'Sales' and 'Temporary_Contractors'. The effective permissions tool on the folder shows that Alice should have Read access. However, she still cannot access the share. Which of the following is the most likely cause of Alice's access denial and the appropriate next step to resolve it?
Medium17A virtualized server running multiple VMs experiences a sudden performance degradation during peak hours. Storage latency spikes and CPU ready time increases significantly. The hypervisor shows high memory overcommitment but no swapping. Which action would most likely resolve the issue without adding hardware?
Hard18You are the lead server administrator for a mid-sized e-commerce company. The web application is hosted on a farm of four Linux servers running Apache, fronted by a hardware load balancer. The load balancer currently uses a round-robin algorithm. Recently, the customer support team has received numerous complaints about slow page load times and occasional timeouts during checkout. You log into the server monitoring console and observe that one of the web servers, web03, has a CPU utilization consistently above 95%, while the other three servers are at around 30-40%. You connect via SSH to web03 and run the 'top' command, identifying a process named 'imagick' consuming 99% CPU. Further investigation reveals that this process is related to image resizing for product thumbnails, and it appears to have entered an infinite loop due to a malformed image file. Meanwhile, the load balancer continues to send requests to all servers equally, including the overloaded web03, causing some requests to time out. You need to restore performance immediately and prevent recurrence. Which of the following actions should you take?
Hard19A technician receives an urgent alert that a critical file server at a remote branch office has gone offline and is unreachable over the network. The server is accessible via out-of-band IPMI, which indicates that chassis power is present, but the power LED on the server is blinking amber instead of steady green. The IPMI system event log reports "System board voltage regulator failure" as the last critical event before the failure. Attempts to use the remote KVM show no video output, and Wake-on-LAN commands have no effect. The branch office has no on-site IT personnel; the only staff are general office workers with minimal technical training. The earliest a field technician can travel to the site is 48 hours. The main office has an identically configured spare server and a backup image of the file server's system disk. The branch office staff can follow simple plug-and-play instructions if provided. Which of the following is the BEST immediate course of action to restore the file services with minimal downtime?
Easy20A system administrator is notified that a server with a RAID 5 array of four 2TB drives has a single failed drive. The server uses hot-swappable drives and a hardware RAID controller. Which of the following actions should the administrator perform FIRST?
Medium21An organization stores backup tapes at an offsite facility. The tapes contain sensitive customer data. A security audit revealed that tapes were stolen from the facility. Which combination of measures would have MOST effectively prevented unauthorized data access?
Hard22Refer to the exhibit. A server in a well-maintained data center has triggered upper critical and non-recoverable temperature alerts for CPU1. The server's chassis fans are operating at full speed, and the data center ambient temperature is normal. Which of the following is the FIRST action the administrator should take?
Easy23A server in a virtualized environment is experiencing VM performance degradation. The host server has adequate resources. The hypervisor logs show excessive 'ready' time for the CPU. Which of the following is the BEST action to resolve this issue?
Hard24A company has an internal web application running on a Windows Server 2019 IIS server. Recently, users have been experiencing intermittent slow responses and occasional '503 Service Unavailable' errors. The server has 32 GB RAM and currently hosts only this application. The application pool is configured to use a private memory limit of 2 GB and a request queue limit of 1000. Performance monitoring reveals that the application pool's private memory gradually increases over several hours until it reaches 2 GB, at which point the pool recycles. The slow responses and errors coincide with the recycling events. The administrator suspects a memory leak in the application code but cannot modify the application immediately. The server must remain available during business hours (8 AM to 8 PM). Which of the following is the best short-term mitigation?
Easy25A server administrator is troubleshooting a performance issue on a VMware vSphere host. The host has multiple VMs, and one VM is experiencing high latency on its virtual disk. The administrator checks the datastore and sees it is a RAID 5 array of 4 SAS drives with 50% utilization. Latency for the VM's virtual disk is reported as 200ms. Which action would most likely improve performance?
Hard26Refer to the exhibit. A backup administrator scheduled a nightly backup to a network share. The backup job fails with the error shown in the log. What is the most likely cause?
Easy27A small accounting firm has a single server that hosts their client database and financial applications. The server is backed up nightly using a full backup to an external USB hard drive, which is stored on a shelf next to the server. Last month, a fire broke out in the office, completely destroying the server and the backup drive. The company lost all data since their last offsite backup, which was six months old because they occasionally took a copy home. The business owner wants to prevent such a catastrophic data loss in the future but is concerned about cost and complexity. They have a limited IT budget and no dedicated IT staff. The firm operates 9-5 Monday to Friday, and can tolerate up to 24 hours of downtime and up to one day of data loss. After the fire, they had to rebuild their client records from paper files, which took weeks. The owner realizes the importance of an offsite backup routine but cannot afford an expensive cloud service or a second server. The firm's internet connection is a basic DSL line with limited upload bandwidth, making large cloud backups slow. The server has a single internal drive with enough free space to store additional copies. Which of the following backup strategies would best meet the firm’s recovery objectives while minimizing cost and complexity?
Easy28A small law firm has a single Windows Server 2016 Essentials server that functions as a domain controller and file server. After a sudden power outage over the weekend, the server does not boot normally. Instead, it displays a black screen with the message: 'BOOTMGR is missing. Press Ctrl+Alt+Del to restart.' The IT support specialist arrives on Monday morning to find the server in this state. The firm's operations are at a standstill because all case files and email archives are inaccessible. The specialist has access to the Windows Server 2016 installation media and a recent system state backup stored on an external drive. The server hardware passed POST, and all disks are detected in the BIOS. The specialist needs to restore the server's ability to boot into Windows as quickly as possible, with minimal risk to existing data. Which of the following procedures should the specialist perform FIRST?
Easy29A server administrator is responsible for protecting sensitive data. The backup process copies files to a network share daily. Which of the following should the administrator do to BEST ensure the confidentiality of the backup data both during transfer and at rest?
Medium30A financial services firm requires zero data loss in the event of a primary data center failure. They operate two data centers 50 miles apart connected by a high-bandwidth, low-latency link. Which replication method should they use to meet this requirement?
Medium31A database server hosts a critical application that requires a recovery point objective (RPO) of 4 hours. The company wants to minimize the impact on production performance during backups. Which backup strategy should be implemented?
Easy32After a thunderstorm, a server in a remote office is reachable via remote console but has no network connectivity. The network switch port shows a steady link light, but the server's NIC shows no link light. Which of the following is the MOST likely cause?
Medium33A company operates a Windows Server 2019 machine that functions as a domain controller and file server. Over the past week, the server has randomly rebooted several times, often during periods of heavy file access. The administrator reviews the System event log and finds multiple Event ID 41 (Kernel-Power) entries with no preceding critical errors. The server is connected to an uninterruptible power supply (UPS) that reports stable input voltage. The server room temperature sensors indicate normal ambient temperature (22°C / 72°F). The server hardware is three years old and has not had any recent changes. The administrator has already run a full antivirus scan with no threats found. Which of the following should the administrator do NEXT to diagnose the issue?
Hard34A healthcare provider is reviewing its disaster recovery strategy. They have two data centers: one primary in City A and a secondary in City B, 200 miles apart. Currently, they perform daily backups that are replicated to City B each night. In the event of a primary site failure, they can fail over to City B, but there is a 4-hour RTO due to manual processes. Their new RTO target is 2 hours, with an RPO of 15 minutes. The IT team is considering various replication technologies. The provider runs a mix of Windows and Linux servers hosting electronic health records (EHR), PACS imaging, and billing applications. Their current backup scheme is a full backup each night, with transaction logs backed up every 6 hours, but these are not immediately shipped offsite. They have experienced power outages in City A, prompting the review. The IT director is concerned about data consistency and quick recovery. The secondary site currently has sufficient hardware to run all critical applications, but data is only updated nightly. The link between data centers has 100 Mbps bandwidth and 10 ms latency, and upgrading it would cost $50,000. The existing staff can script failover procedures. Which solution best meets the new RPO and RTO while staying within budget?
Medium35A system administrator configures full backups on Sunday evenings and differential backups on weekdays. On Thursday morning, a disk failure occurs. Which of the following sets of backups is necessary to completely restore the server's data with the fewest number of backup files?
Medium36A company performs full backups every Sunday and differential backups daily. After a ransomware attack, they discover that both the production data and all attached backup media were encrypted. They need to ensure data can be recovered in the future. Which of the following is the BEST change to their backup strategy?
Medium37A company runs a popular public-facing e-commerce website hosted on a farm of five Windows Server 2019 web servers behind a hardware load balancer. Recently, users have been reporting intermittent '503 Service Unavailable' errors during peak shopping hours. The administrator checks the load balancer and finds that all servers are marked as healthy with low CPU and memory usage. However, when inspecting a sample server, the administrator notices a large number of TCP connections in the TIME_WAIT state, consuming all available ephemeral ports. The application is ASP.NET based and uses IIS. The server configuration is as follows: Windows Server 2019 Standard, 4 vCPUs, 16 GB RAM, default TCP/IP settings. The administrator needs to resolve the connectivity issues without making changes to the application code or altering the network architecture. Which of the following actions should the administrator take to fix the problem PERMANENTLY?
Hard38A company performs annual disaster recovery tests. The last test revealed that the recovery time objective (RTO) was not met because the backup tapes were corrupted. The backup administrator proposes changes to the backup verification process. Which practice is MOST effective to ensure recoverability?
Hard39A small business relies on a single Dell PowerEdge T340 tower server running Windows Server 2019 as its primary domain controller and file server. The server is situated in a locked, air-conditioned IT closet and is protected by an online surge protector. During a severe thunderstorm last evening, the building experienced a momentary power loss. This morning, the administrator found the server completely powered off. When the power button is pressed, the front panel diagnostic LEDs briefly illuminate, and all internal cooling fans start spinning for about two to three seconds, but then the server abruptly powers down. There are no audible beep codes, and the monitor never receives a video signal. The administrator has already verified the power cable is firmly seated in both the server and the surge protector, swapped the power cable with a known-good one, and tested the surge protector with another device, which powered on normally. No spare parts are immediately available, and server downtime must be kept to a minimum. What should the administrator do FIRST to diagnose and resolve the problem?
Easy40A small law firm relies on a single server that hosts a document management system and email. The server is backed up nightly using differential backups to an external USB hard drive that remains connected to the server. One Monday morning, the office manager finds all files encrypted and a ransom note on the screen. The server’s event logs indicate that the encryption began at 2:00 AM on Saturday. The firm’s offsite backup policy rotates two sets of tapes, and the most recent set was taken offsite on Friday evening and is stored in a bank safe deposit box. The USB backup drive, still attached to the server, shows its files also encrypted. The firm does not have a cloud backup service for the server. The office manager wants to restore operations as quickly as possible with minimal data loss and zero risk of reinfection. What is the BEST course of action?
Easy41A database administrator notices that the primary SQL Server instance has been experiencing severe performance degradation over the past hour. The server is a virtual machine with 8 vCPUs and 64 GB of RAM, and it normally operates with around 40% CPU utilization. Currently, Task Manager shows 100% CPU usage, with the sqlservr.exe process consuming nearly all cycles. The database response times have increased tenfold, and some queries are timing out. There are no scheduled maintenance jobs running, and the transaction log backup completed successfully earlier. The DBA checks active sessions and finds one long-running ad-hoc query from a new reporting tool that was deployed this morning. The query is performing a cross join on two large tables with missing WHERE clauses, causing a Cartesian product. Ending the session will roll back the query and free resources.
Medium42A server that uses iSCSI storage has suddenly lost connectivity to all LUNs. The network team confirms no changes have been made. Which of the following is the FIRST step in troubleshooting this issue?
Hard43After a power outage, a server fails to boot and displays a "Missing operating system" error. The server uses RAID 1 for the OS disk. The administrator verifies both drives are present in the RAID configuration utility but one drive is marked as failed. What should the administrator do FIRST?
Easy44A system administrator needs to apply critical security patches to a production web server that cannot be taken offline. The server runs a Linux operating system and hosts a high-availability website. The administrator wants to ensure that if the patches cause a failure, the server can be quickly rolled back to its previous state. Which of the following actions should the administrator take FIRST?
Medium45Which THREE of the following are typically essential elements of a disaster recovery plan (DRP)? (Choose three.)
Hard46A server in the datacenter fails to power on after a scheduled power maintenance. The facility team confirms that power is being supplied to the rack. The server's front panel LED is not illuminated. Which of the following should the administrator check FIRST?
Easy47A junior system administrator is managing a Linux file server running CentOS 7 with logical volumes managed by LVM. The server hosts home directories for 200 users on the /dev/vg_users/lv_home logical volume, mounted at /home. Yesterday, the administrator created an LVM snapshot named home_snap_20250101 of the home logical volume using `lvcreate -L 5G -s -n home_snap_20250101 /dev/vg_users/lv_home` to prepare for a scheduled maintenance. This morning, during a misoperation, the administrator accidentally ran `rm -rf /home/user123`, permanently deleting user123's home directory and all its contents. The snapshot still exists and contains the pre-deletion state of the entire logical volume. The administrator has root access and needs to restore the /home directory to its state as of the snapshot time to recover the lost data. All users are currently logged out and the server can be briefly taken offline if needed. Which of the following procedures should the administrator follow to restore the home directory data from the snapshot with minimal impact and risk?
Easy48A server has been experiencing random crashes and generating memory-related errors in the system event log. The technician has already run memory diagnostics which show frequent errors on a single DIMM. The server has four DIMMs installed. Which of the following is the BEST next step?
Hard49A server administrator is troubleshooting an issue where a database server's performance degrades every night at 2 AM. Resource monitor shows high disk I/O and CPU usage during that time. There are no scheduled tasks on the server. Which of the following should the administrator investigate FIRST?
Easy50A server has two NICs configured in a team using LACP. The server loses network connectivity when one NIC is physically disconnected, even though both links show as active in the teaming software before the failure. What is the most likely cause of the issue?
Hard51A server uses NIC teaming with LACP (802.3ad) for load balancing and failover. After replacing a failed switch with a new switch of the same model, the server loses network connectivity. The switch ports show no activity. Which of the following is the MOST likely cause?
Hard52Several users report sluggish performance from a database server. The server administrator notices that the CPU fans are running at maximum speed and the baseboard management controller (BMC) reports CPU temperatures of 85°C even at idle. The administrator already cleaned dust from the chassis and verified all fans are operational. Which of the following should the administrator do NEXT?
Hard53A VMware ESXi host runs six virtual machines, each configured with 8GB of RAM, totaling 48GB allocated. The host physically has 32GB of RAM, and memory overcommitment is enabled. Recently, a critical VM experienced severe performance degradation during peak hours, with the guest OS showing high memory pressure and balloon driver activity, while other VMs showed moderate usage. Which of the following actions will BEST resolve the issue without compromising other VMs?
Hard54A server administrator is tasked with ensuring that a critical database server remains available in the event of a hardware failure. The solution must provide automatic failover with minimal administrative overhead. Which of the following should be implemented?
Easy55A medium-sized company uses a backup strategy that includes a full backup every Sunday at 2:00 AM and differential backups Monday through Saturday at 2:00 AM. The backups are written to a network-attached storage (NAS) device. On Thursday morning, the company experiences a ransomware attack that encrypts all data on the file server, including the NAS. The administrator needs to restore the file server with minimal data loss. The last successful full backup was from the previous Sunday, and differential backups were successful on Monday, Tuesday, and Wednesday. However, Thursday's differential was not completed because the attack occurred before the scheduled time. The administrator attempts to restore using the Sunday full backup and Thursday's differential, but the restore fails because the differential backup on the NAS is also encrypted. Which of the following is the best course of action?
Hard56A server administrator receives reports that a production server is shutting down unexpectedly after running for several hours. The server is a 2U rackmount unit located in a data center with proper ambient cooling (20°C/68°F). The server has redundant power supplies connected to separate PDUs and no power anomalies are reported. The administrator checks the operating system event logs and finds a critical log entry: 'The system was shut down due to a thermal event.' However, the CPU temperature logs show that the CPU was at 47°C at the time of shutdown, and the chassis inlet temperature was 23°C. The server's internal fans are running at high speed and are clearly audible. The administrator suspects a thermal issue but is unsure why the CPU is not showing high temperature. The server has a baseboard management controller (BMC) that monitors various sensors. Which of the following components should the administrator investigate FIRST to identify the likely cause of the shutdown?
Medium57After installing additional RAM modules in a server, the BIOS displays only a portion of the installed memory. The modules are identical in speed and size but from different manufacturers. Which of the following is the BEST initial troubleshooting step?
Medium58A server with a RAID 5 array of four disks reports a degraded logical drive. The technician replaces the failed disk and rebuilds the array. After the rebuild completes, the array is still degraded. Which of the following is the most likely cause?
Medium59Refer to the exhibit. During boot, the server displays this error and shuts down. Which of the following is the most likely cause?
Medium60Refer to the exhibit. What is the most likely cause of this error?
Medium61A corporation's backup strategy currently involves a weekly full backup every Saturday night and daily differential backups Monday through Friday. The company has a 5 TB dataset with a daily change rate of about 10%. The full backup takes 12 hours and runs into Monday morning, impacting production performance. The backup window is from 10 PM to 6 AM. The company requires faster backups that can complete within the window, and they also want an offsite copy of the backups for disaster recovery. The existing backup server has direct-attached disk storage and a tape library. The network bandwidth to the offsite location is limited to 100 Mbps. The administrator is evaluating changes to the backup methodology and infrastructure to meet these requirements. Which of the following solutions best addresses the speed and offsite requirements?
Hard62A server configured with dual redundant power supplies unexpectedly shuts down when one power supply fails. Both power supplies are rated for the server's total load and were functioning before the failure. What is the MOST likely reason for the shutdown?
Hard63A technician is troubleshooting a server that fails to boot. The server displays a 'Boot Device Not Found' error. The technician verifies that the hard drives are spinning and appear in the RAID controller's BIOS. What should the technician check next?
Medium64Refer to the exhibit. An administrator is reviewing logs after a server experienced performance issues and unexpected shutdowns. Based on the log entries, which component is MOST likely failing?
Medium65Refer to the exhibit. An administrator receives reports that a web application is returning HTTP 502 errors. The administrator examines the Nginx error log on the reverse proxy server and sees the following. Which of the following is MOST likely causing the errors?
Hard66A server running a critical database application crashes and fails to boot with the error message 'Operating System not found.' The server is equipped with a hardware RAID 5 array consisting of three identical disks. A technician suspects a disk failure. What is the MOST likely cause of this error?
Hard67A company uses a two-node failover cluster for a critical application. The cluster nodes are located in the same data center, and the quorum configuration uses a file share witness on a separate server in the same data center. During a major power outage, both cluster nodes and the file share witness server lose power. What is the impact on cluster availability?
Hard68A server administrator notices that a database server is responding slowly to queries. The CPU utilization is at 30%, memory at 40%, and disk latency is normal. Which of the following should the administrator check NEXT?
Easy69A small business relies on a tower server that acts as a file and print server for 15 employees. The server has a single Intel Xeon E-2300 series processor, four 16GB DDR4 ECC RDIMMs installed in dual-channel configuration, and two 2TB 7200 RPM SATA hard drives in a hardware RAID 1 mirror. The power supply unit (PSU) is a 500W 80+ Bronze unit that is about four years old. Recently, the server has started experiencing random, intermittent crashes resulting in a blue screen, typically during periods of heavy disk I/O, such as when multiple users access large files. Event Viewer logs show occasional corrected memory errors (ECC events) but no uncorrected errors. The administrator runs MemTest86+ on all four DIMMs for multiple passes, and no errors are detected. The server room ambient temperature is normal, and all fans are operating. The crashes are becoming more frequent. Which of the following actions would MOST likely resolve the underlying issue?
Hard70A company is planning to deploy a new web application on multiple servers behind a load balancer. The application requires consistent session data across all servers for seamless user experience. Which of the following solutions would BEST meet this requirement?
Hard71A medium-sized e-commerce company operates three critical servers: a web front-end, a database server, and a file server. Currently, a full backup of all servers is performed every Sunday starting at 11:00 PM and completes in about 6 hours. Differential backups run each weekday at 11:00 PM, taking roughly 2 hours. On a Wednesday at 10:00 AM, a ransomware attack encrypts all data on all servers. The IT team’s incident response plan requires restoration with an RPO of 4 hours and an RTO of 8 hours. The latest clean backup is Tuesday’s differential, resulting in approximately 10 hours of data loss. Future attacks could occur at any time. Management is willing to spend up to $200 per month to improve the backup strategy but cannot afford new hardware or a dedicated hot site. The team needs a solution that reduces both RPO and RTO within budget while maintaining simplicity for a small IT staff of two. Which of the following backup strategies should be implemented to best meet these requirements?
Hard72An administrator is monitoring a server that has a hardware RAID 5 array consisting of four 2 TB disks. The RAID controller's management software reports that one disk has a status of 'Pred Fail' (predictive failure). The array also has a dedicated hot spare disk already installed and set up. The array is still fully functional with no data loss, but the 'Pred Fail' warning indicates the disk is likely to fail soon. The server is a production database server that cannot be taken offline except for scheduled maintenance windows, which are not until the following weekend. The administrator needs to ensure data integrity and avoid any risk of downtime or data loss while waiting for the replacement. Which immediate action should the administrator take?
Medium73A MySQL database server on Linux is experiencing high CPU utilization during peak business hours. Upon investigation, the administrator finds that the query cache hit ratio is below 20%, and the query_cache_size is set to 0. The server has 64 GB of RAM and the database workload is primarily read-heavy. Which of the following actions should the administrator take FIRST to improve performance?
Hard74A technician is troubleshooting a server that is experiencing high disk I/O wait times. The disk queue length is consistently above 10. Which of the following is the MOST likely cause?
Medium75A database server with 64 GB of RAM and RAID 5 storage is experiencing intermittent performance degradation. System monitoring shows constant 95% memory utilization, high disk queue length, and frequent page faults. The server is running a critical application that cannot be restarted during business hours. Which action will provide the BEST permanent resolution?
Hard76A technician is replacing a failed hard drive in a hot-swap RAID 5 array. After inserting the new drive, the RAID controller does not automatically rebuild. What should the technician do first?
Hard77A medium-size enterprise runs a vSphere 7.0 cluster with two hosts (HostA and HostB) for production VMs. Each host has two 10GbE uplinks (vmnic0 and vmnic1) connected to separate physical switches (SW1 and SW2) for redundancy. A single vSphere standard switch (vSwitch0) uses both uplinks with teaming policy set to 'Route based on originating virtual port ID,' 'Network failure detection: Link status only,' and 'Notify switches: Yes.' Lately, several VMs running on HostA experience intermittent network disconnections lasting 20–30 seconds, while VMs on HostB are unaffected. The administrator checks vCenter events and sees repeated messages: 'Lost uplink redundancy on vSwitch0. vmnic0 is down.' followed seconds later by 'Uplink redundancy restored. vmnic0 is up.' The physical switch SW1's log shows the port for vmnic0 transitions through spanning-tree listening and learning states each time this occurs, taking about 15 seconds. The link is a trunk allowing all necessary VLANs, with no errors or security violations. The network team has already swapped the fiber cable and SFP+ transceiver for vmnic0 without improvement. The VMs affected are those whose virtual ports are pinned to vmnic0 by the load-balancing policy; VMs pinned to vmnic1 never experience disconnections. The administrator has also rebooted HostA and updated the NIC firmware, but the flapping continues. What should the administrator do to permanently resolve the intermittent connectivity?
Medium78A technician is installing a new 2U server into a datacenter rack. The server is equipped with redundant power supplies. According to best practices for power redundancy, how should the technician connect the power supplies?
Easy79Refer to the exhibit. A server administrator configured iptables rules on a Linux server. Immediately afterward, they are unable to connect to the server via SSH. The output of 'iptables -L INPUT -n' is shown. What is the most likely cause of the connectivity issue?
Medium80A company is migrating a legacy line-of-business application from Windows Server 2012 R2 to a new Windows Server 2022 server that is a member of an Active Directory domain. The application runs as a Windows service under a domain service account named CORP\svc_app. The service account has been granted the 'Log on as a service' user right on the old server, and the application is configured to listen on a static TCP port 8443. After installing the application on the new server and configuring it with the same service account and port, the application fails to start. The administrator checks the Windows Event Viewer and sees two errors in the System log: 'The CORP\svc_app service failed to start due to the following error: The service did not start due to a logon failure' and 'The service cannot bind to the designated port 8443'. The administrator has already verified that the service account's password is correct and has not expired, that the account is enabled, that the port 8443 is not being used by another service, and that the Windows Firewall has an inbound rule allowing traffic on port 8443. The application's configuration file correctly points to port 8443. What should the administrator do to resolve the issue?
Hard81Refer to the exhibit. A technician reviewing the server's storage array status sees the above output. The server is using a hot spare with a RAID 5 array. What should the technician do NEXT?
Hard82A small business has a single file server running Windows Server 2019. The server uses two internal SATA drives in a RAID 1 mirror for the operating system and data. The company's backup solution performs a full backup every night to an external USB hard drive, which is stored in the server room. The IT administrator recently noticed that the server's system volume is running low on space and decides to migrate the data to a larger drive. During the migration, the server crashes and will not boot. The administrator attempts to restore from the latest backup but finds that the backup drive is corrupted and cannot be read. The company has no offsite backups. What should the administrator have done to prevent this situation?
Easy83A large enterprise uses a centralized backup solution with a backup server running Commvault. Backups are stored on a deduplicated disk array and replicated to a secondary site for disaster recovery. The company's security team detects ransomware activity that has encrypted several file servers. The backup administrator checks the backup repository and finds that the backup data is also encrypted because the backup service account had permissions to modify backup files, and the ransomware propagated to the repository. The last known good backup is from two weeks ago, which is too old for the organization's RPO of 24 hours. The backup administrator is under pressure to restore operations quickly. Which of the following should the administrator implement to prevent this from recurring?
Hard84A server has been randomly rebooting several times a day with no pattern. The administrator reviews the IPMI System Event Log and finds multiple 'Correctable ECC error' entries for DIMM slot B2. The server memory is configured with 16 DIMMs of the same type and manufacturer, all recently installed. What should the administrator do FIRST to resolve this issue?
Hard85A server administrator is troubleshooting a physical server that randomly crashes once or twice a week. The administrator has already verified that the power supply is functioning correctly and has checked the event logs for critical errors. According to standard troubleshooting methodology, what should the administrator do next?
Medium86Refer to the exhibit. A technician receives an alert from the monitoring system showing the error in the exhibit. The server is still online, but performance has degraded. Which of the following is the MOST likely cause and appropriate action?
Hard87A RAID 5 array is degraded due to a failed disk. What is the best practice for recovery?
Hard88An administrator notices that a Linux server's /var/log/messages file is filled with repeated "eth0: link up" and "eth0: link down" entries every few seconds. The server is connected to a managed switch. Which of the following is the most likely cause?
Medium89A server hosts a database that requires nightly backups. The backup strategy uses a full backup every Sunday and differential backups on other days. On Wednesday, the server fails. Which backup sets are required to restore to the most recent state?
Medium90A server configured with RAID 5 has two failed drives. The array is offline and critical data is inaccessible. The administrator has replacement drives available. What should the administrator do to restore the data and array with minimal data loss?
Medium91A medium-sized company runs an e-commerce platform on a cluster of three physical servers hosting virtual machines. The disaster recovery plan includes daily backups to a remote data center using Veeam Backup & Replication. The company's annual disaster recovery drill is scheduled for next week. During the drill, the IT team plans to simulate a complete site failure by powering off the primary data center. The recovery time objective (RTO) is 4 hours, and the recovery point objective (RPO) is 1 hour. The team successfully restores the VMs at the remote site, but the application experiences significant performance degradation and many transactions fail due to database inconsistency. Investigation reveals that the backup was taken at 2:00 AM, but the failure occurred at 10:00 AM, and the application's database had transactions between 2:00 AM and 10:00 AM that were not captured. What should the IT team do to improve the recovery process?
Medium92A server administrator is troubleshooting a network connectivity issue on a server that has recently been moved to a different rack. The server can ping its own IP address but cannot ping the default gateway. Which of the following is the MOST likely cause?
Easy93A technician installs additional RAM in a server. After powering on, the server emits a continuous beep code and does not POST. The server documentation indicates this beep code signifies a memory error. Which of the following is the MOST likely cause?
Medium94Refer to the exhibit. A backup job to a network share failed. The administrator reviews the backup log. What is the most likely cause of the failure?
Medium95A server administrator is troubleshooting a network connectivity issue where a newly installed server cannot communicate with other devices on the same subnet. The server has a static IP address configured. Other devices on the same switch can communicate. Which TWO of the following could be the cause of the issue? (Select TWO)
Medium96A technician is troubleshooting a server that fails to boot after a scheduled power outage. The server is connected to a UPS. Upon pressing the power button, the server powers on briefly (fans spin, lights flash) and then shuts down after 2 seconds. The POST does not complete. The server has a dual power supply with each connected to a separate PDU. Which of the following is the MOST likely cause?
Hard97Refer to the exhibit. The Print Spooler service on a critical Windows Server 2019 fails to start at every boot. The server was recently updated with the latest cumulative patch. Which of the following is the MOST likely cause?
Hard98Refer to the exhibit. A server technician sees the following output. What is the current status of the RAID array?
Easy99A medium-sized organization runs several critical virtual machines on a Windows Server 2019 Hyper-V host with 64 GB of RAM and two 12-core processors. One of the VMs, a database server, has been experiencing intermittent performance degradation, specifically during peak hours. The VM is configured with 4 vCPUs and 16 GB of static memory. The host's overall CPU utilization rarely exceeds 40%, and memory usage is around 50%. The administrator logs into the host and checks the VM's CPU usage in Hyper-V Manager, which shows it averaging 65% with occasional spikes to 95%. However, inside the VM, Task Manager shows constant 95-100% CPU usage on all logical processors. No other VMs are reporting performance issues. The administrator needs to determine the root cause and apply a fix that does not involve adding more physical resources or rebooting the production VM during business hours. Which of the following actions should the administrator take?
Hard100A server fails to boot after installing new memory. The POST beep code indicates a memory error. What is the most likely cause?
Easy101Refer to the exhibit. A server administrator receives reports that an internal web server is inaccessible. After connecting locally, the administrator runs a command and receives the following output. Which of the following commands would best resolve the issue?
Medium102A server administrator needs to set up out-of-band management for a new server. Which THREE of the following are essential for successful configuration and remote access? (Choose three.)
Hard103A financial services firm requires a disaster recovery solution that provides a Recovery Point Objective (RPO) of near zero and a Recovery Time Objective (RTO) of less than 2 hours. Which of the following site types is MOST appropriate?
Easy104Refer to the exhibit. A Windows file server at a branch office lost network connectivity after a scheduled reboot. The administrator logs in via the console and runs `ipconfig /all`, which shows the output in the exhibit. The server should have a static IP of 10.0.0.50. What should the administrator do to restore connectivity?
Easy105A server cannot connect to a specific network share. The administrator can successfully ping the server's IP address from the client. Which of the following is MOST likely causing the issue?
Medium106A server technician replaces a failed RAM module with an identical spare. After installation, the server powers on but emits continuous short beeps and does not complete POST. Which of the following is the MOST likely cause?
Easy107A technician is troubleshooting a server that fails to boot after a power outage. The server displays a "Non-system disk or disk error" message. Which action should the technician take first?
Medium108A server technician is mounting a 4U server in a standard 19-inch rack. Which of the following safety precautions is MOST important before lifting the server into place?
Easy109A regional hospital operates two data centers located 10 miles apart, with synchronous replication of critical patient record systems between them. The replication ensures that any write to the primary storage is immediately mirrored to the secondary site. The hospital also maintains weekly full backups to LTO-8 tapes, which are stored in a fireproof safe at an offsite warehouse 30 miles away. The IT team has not implemented storage snapshots or continuous data protection due to budget constraints. Last week, a ransomware attack encrypted all files on the primary site. The replication process promptly mirrored the encrypted data to the secondary site, rendering both copies inaccessible. The attackers demanded $500,000 in Bitcoin. The hospital's disaster recovery plan specifies an RPO of 1 hour and an RTO of 4 hours. The IT director must now choose a restoration strategy that minimizes data loss and downtime while ensuring a clean, malware-free environment. The backup tapes are confirmed to be unencrypted and free of ransomware. Which of the following actions should the IT director take first?
Medium110A server running a critical application fails to boot with the error: 'Boot device not found.' The server uses UEFI and a RAID 5 array for the OS. The administrator verifies that all disks are present and powered. Which of the following should the administrator check FIRST?
Hard111A server administrator is upgrading the RAM on a server that supports quad-channel memory architecture. They install four identical 16GB DDR4 ECC modules, but the server only recognizes the memory as operating in single-channel mode. Which of the following is the most likely cause?
Medium112A technician is troubleshooting a server that fails to boot. The server powers on, fans spin, but no video output and no beep codes. The technician reseats the RAM and GPU, but the issue persists. Which of the following should the technician check NEXT?
Medium113Following a firmware update on a server's RAID controller, the server fails to boot and reports "No boot device found." The RAID array status shows healthy in the controller BIOS. Which THREE of the following actions should the administrator take to resolve the issue? (Choose three.)
Hard114A technician is installing a new server for a department. The server will run a single application that requires high reliability. The operating system should be protected against a single disk failure without sacrificing read performance. Which RAID configuration is MOST appropriate?
Easy115A server fails to boot with an 'Operating System Not Found' error. The BIOS detects the hard drive. What is the MOST likely cause?
Easy116A server is running out of disk space on the system drive (C:). The server is running Windows Server 2019. The IT manager wants to add more space without downtime. The server has one free SATA port and one available drive bay. Which of the following is the BEST solution?
Medium117A company uses a two-node failover cluster for a critical database application. The cluster consists of Node A and Node B, with shared storage connected via SAS. During a routine check, the administrator discovers that Node A has failed and the cluster resources did not fail over to Node B. The cluster service is running on Node B, but the database resource remains offline. Node B can successfully ping Node A's management IP address but not the dedicated cluster heartbeat IP. The shared storage appears in the operating system on Node B, but attempts to bring the disks online fail. The administrator must restore database service as quickly as possible. Which of the following actions should the administrator take FIRST?
Hard118A small business has purchased a new server to function as a file server for 25 employees. The server is equipped with four 1TB SATA hard disk drives and no hardware RAID controller; the operating system supports software RAID. The business owner's primary requirements are data redundancy to protect against a single drive failure and maximum usable storage capacity, while keeping costs low. The IT technician is tasked with configuring the storage. The technician evaluates the following options: RAID 0 striping across all four drives; RAID 1 mirroring using two pairs (drives 1+2 mirrored, drives 3+4 mirrored), providing two separate volumes; RAID 5 with parity across all four drives; and RAID 10 combining mirroring and striping. The technician needs to recommend the configuration that best meets the requirements. Which of the following should the technician implement?
Easy119A technician is monitoring a server with a RAID 5 array that has a hot spare. One of the drives fails. Which of the following actions will occur automatically in this configuration?
Easy120A server fails to power on after a technician replaced the power supply unit (PSU). The technician notices the server's LEDs are off and no fans are spinning. Which of the following should the technician do FIRST?
Medium121A server administrator notices that a database server is experiencing high CPU usage at specific times of the day. After checking logs, the administrator finds that a report generation task scheduled at those times is causing the issue. The task cannot be rescheduled or optimized further. Which of the following actions should the administrator take to ensure the server remains responsive for other applications during peak usage?
Medium122A small business plans to deploy a new on-premises server for a virtualization environment. The server will run a hypervisor hosting four virtual machines: a domain controller, a file server, a web application server, and an SQL database server. The business expects moderate workloads and needs to ensure reliable performance and data protection. The procurement department has proposed the following server configuration: single Intel Xeon E-2300 series CPU (4 cores, 8 threads), 16 GB DDR4 ECC RAM, two 1 TB SATA hard drives configured in RAID 1, a single 1 GbE network interface, and a 500W power supply. The IT manager reviews the proposal and identifies several deficiencies that will not meet the expected workload requirements. Which of the following changes to the server configuration is the MOST important to address first to ensure the VMs can run effectively?
Medium123A company has a virtualized server environment with two physical hosts running VMware vSphere. Each host has 2 CPUs, 128GB RAM, and 6x 600GB SAS drives in RAID 10. Recently, host A experienced a power surge that caused it to shut down abruptly. After restarting, the host boots but the RAID controller reports that one of the drives in the RAID 10 array is missing. The administrator has a replacement drive of the same model. What should the administrator do first?
Hard124A small business has a limited budget and can tolerate up to 72 hours of downtime in the event of a disaster. Which type of disaster recovery site would be most cost-effective?
Easy125A junior administrator is managing a Linux server used by a development team. The root filesystem (/) has reached 98% capacity, causing the system to slow down and some applications to fail. The server has an LVM volume group with 20 GB of free space, but the root logical volume is 50 GB with an ext4 filesystem. The administrator needs to free space quickly and safely without rebooting or adding new disks. They log in via SSH and want to identify where the large files are and then take action. There are concerns about accidentally deleting critical system files or logs that might be needed for auditing. The server has the following typical directories: /var (with logs), /home (user files), /opt (application files), /tmp. Which of the following sequences of actions is the most appropriate to resolve the issue?
Easy126A financial services firm requires a disaster recovery site that provides immediate failover with zero data loss. Which type of site should they implement?
Medium127A mid-sized manufacturing company operates a primary data center with all critical servers. They have a warm standby site located 100 miles away. For databases, the primary SAN uses synchronous replication to the standby SAN; no tape backups are taken for databases. File and application servers are backed up to an on-premises tape library using nightly incrementals with a weekly full backup every Sunday. Tapes are shipped off-site every Monday morning. On Tuesday morning, a ransomware attack encrypts the entire primary SAN. Because of the real-time replication, the standby SAN is encrypted almost instantly. The on-site tape library is also connected to the network and its tapes, including Sunday's full and Monday's incremental, are encrypted by the attack. The most recent off-site shipment was the previous Monday (eleven days ago), meaning the off-site tapes contain a full backup from eleven days ago and daily incrementals up to that point. The company's RPO is 1 hour for databases and 24 hours for file servers; RTO is 8 hours. The IT director must decide the best immediate course of action to restore operations while adhering to the DR plan as closely as possible.
Medium128You are a server administrator at a mid-sized company that hosts its own on-premises Exchange server and file server. The infrastructure consists of three racks: Rack A contains the core switches and firewalls, Rack B contains the Exchange server (Dell PowerEdge R740) and the file server (HP ProLiant DL380 Gen10), and Rack C contains backup devices and a tape library. The data center cooling is provided by a raised-floor system with perforated tiles. Recently, the file server has been experiencing random shutdowns during peak usage hours (10 AM to 2 PM). The shutdowns are preceded by system event log warnings indicating that the CPU temperature has exceeded the threshold. The ambient temperature around the rack is 20°C (68°F) as measured by a handheld thermometer. Other servers in Rack B do not exhibit this behavior. The file server is a 2U server with two Xeon processors, 128 GB RAM, and six hot-swap SATA drives. It runs Windows Server 2019. The server has been in service for three years with no prior issues. The data center manager has noted that the perforated tiles are clear of obstructions. You have verified that the fans in the file server are spinning and the internal air filters are clean. Which of the following is the MOST likely cause of the overheating issue?
Medium129The Coho Vineyard company operates a two-node Windows Server failover cluster to provide high availability for a critical SQL database. Node A has been running the database workload without issues, while Node B was taken offline two weeks ago due to a memory module failure. The faulty memory was replaced, and Node B was powered on. The administrator verified that Node B boots correctly, the network links are up, and the cluster service is running. However, the database role fails to start on Node B. Checking the cluster logs reveals that Node B cannot join the cluster, and the event 'Cluster service has lost quorum' is recorded. The administrator confirms both nodes can ping each other and access the shared SAN storage, but the cluster disk resource appears as 'Offline' on Node B. What should the administrator do to resolve the issue and bring the database online?
Hard130A Linux database server has recently exhibited sluggish response times. An analysis of system performance shows high CPU wait I/O, frequent page swapping, and a low cache hit ratio. The server has 16GB of RAM, and the database itself stores 100GB of active data. Which of the following is the MOST effective long-term solution to improve performance?
Hard131A medium-sized business runs a critical internal application on a single physical server running Windows Server 2019. The application is memory-intensive, often using up to 24 GB out of 32 GB RAM during peak hours. Over the past week, the server has experienced three unexpected reboots, each occurring during peak load. The server is not part of a cluster, and all data is stored on local disks. You have checked the Windows System event log and found Event ID 41 (Kernel-Power) indicating an unexpected shutdown. There are no related critical errors in the Application log. You have also reviewed the server's firmware logs and found multiple corrected memory errors (ECC) over the last month, with an increase in frequency just before each crash. The server is under warranty, and the hardware vendor's diagnostic tools report a failing memory module in DIMM slot A1. The vendor has recommended replacing the faulty DIMM immediately. However, the server is currently processing critical end-of-quarter financial reports that cannot be interrupted for at least 6 hours. Which of the following is the BEST course of action to minimize risk of data loss and downtime until a planned maintenance window?
Medium132A server displays a 'CMOS battery low' error during POST. After the technician replaces the CR2032 battery with a new one, the server still loses date and time settings when disconnected from power. Which of the following should the technician try NEXT?
Medium133After applying a Windows security patch, a server fails to boot and displays 'Bootmgr is missing'. The server is UEFI-based. Which of the following is the MOST efficient way to resolve the issue?
Hard134Your organization is migrating a Windows Server 2019 file server with 2 TB of shared data to a new server running Windows Server 2022. The migration must minimize user downtime and ensure file permissions are preserved. Users access files during business hours (8 AM to 6 PM) and the migration must be completed within a four-hour window starting at 10 PM on Saturday. You plan to use DFS Replication (DFSR) for initial data copy and then perform a final synchronization during the cutover. After setting up DFSR between the old and new servers, you realize that the initial replication will take approximately 12 hours due to the large number of files. What should you do to complete the migration within the allowed window?
Hard135A server technician has just replaced a failed hard drive in a RAID 5 array. After inserting the new drive, the array begins rebuilding, but after 10 minutes, the rebuild fails and the array status shows 'degraded' again. Which of the following is the MOST likely cause?
Easy136A network administrator needs to configure centralized authentication for network devices. The solution must provide encryption of the entire authentication process, support for multiple protocols, and accounting of user actions. Which protocol should be used?
Hard137A system administrator needs to configure secure remote access to servers in the data center. The current setup uses password-based SSH, but the security policy mandates multifactor authentication and prevention of brute-force attacks. Which solution best meets these requirements?
Medium138An organization has a server with a hardware RAID 5 array consisting of four 2 TB SAS drives. The server hosts a critical database and is configured with a hot spare. During routine monitoring, the storage administrator discovers that one drive has failed and the hot spare has automatically taken over, with the array currently rebuilding. However, the rebuild process repeatedly fails at approximately 30% completion, and the RAID controller logs show I/O errors on the hot spare drive. The failed drive was replaced with an identical model from inventory, and the rebuild was restarted, but it again fails at the same point. All other drives show healthy SMART status, and the server's firmware and RAID controller firmware are up to date. The database is still online and functioning, but the array is running in a degraded state, putting data at risk. The server is located in a remote data center without onsite staff, and a maintenance window is scheduled in three days.
Hard139A system administrator notices unusual file encryption activity on a file server. The activity appears to be rapidly spreading to other servers, and ransom notes are appearing. Which of the following should the administrator do FIRST?
Hard140After a brief power outage, a server does not power on when the power button is pressed. The power supply LED indicator is green, but the internal fans do not spin and there is no video output. Which of the following is the MOST appropriate troubleshooting step?
Medium141Refer to the exhibit. A server is running slowly. Based on the memory statistics, what is the MOST likely issue?
Medium142Refer to the exhibit. A Linux server's local firewall is configured as shown. The administrator is unable to perform backups to a network-attached storage (NAS) device using TCP port 10000. Which firewall rule is causing the issue?
Hard143A server with dual redundant power supplies shuts down unexpectedly. One power supply has a solid amber LED. What is the most likely cause?
Easy144A small business needs a disaster recovery site that can be brought online within 2 hours of a primary site failure. The business can tolerate minimal data loss. Which type of recovery site should they implement?
Easy145Refer to the exhibit. A server administrator is troubleshooting a DNS resolution issue on a Windows Server 2019. The exhibit shows the output of the command `nslookup` queried against the server's own IP. Based on the output, what is the most likely cause of the resolution failure?
Hard146Refer to the exhibit. A server administrator runs a dmidecode command to check memory configuration and obtains the output shown. The system supports DDR4-2666, but all DIMMs are running at 1866 MT/s. Which action will allow the memory to run at the maximum supported speed?
Hard147A server administrator configures a scheduled task to back up a database using a command-line tool. The task runs successfully when executed manually, but fails when run via the task scheduler. The log shows 'Error: Access denied.' What is the MOST likely cause?
Medium148A server logged the warning shown in the exhibit. Which of the following should the technician check first?
Easy149Refer to the exhibit. A server administrator encounters an authentication issue when accessing a web server. The exhibit shows an error from the Domain Controller's event log. What is the most likely cause of the problem?
Hard150An administrator needs to remotely manage several Linux servers securely without using passwords. Which of the following is the BEST method?
Easy151A user attempts to access a shared folder named \\Server\Finance. The share permissions are set to 'Everyone – Full Control'. The NTFS permissions on the folder grant the user 'Read & Execute' but deny 'Write'. What is the user's effective permission when accessing the share over the network?
Easy152A web application server is experiencing intermittent 502 Bad Gateway errors during peak usage hours. The server's reverse proxy logs show connections to the backend application server being refused. The application server's resource monitor shows CPU utilization at 95% and memory utilization at 40%. Which of the following actions is MOST likely to resolve the issue?
Hard153Which TWO of the following are considered best practices for securing a server's remote management access?
Medium154A server has a RAID 5 array with four drives. One drive fails and is replaced. During the rebuild, a second drive reports a media error and the rebuild fails. What should the administrator do FIRST to minimize the risk of permanent data loss?
Hard155A company performs a full backup on Sunday and incremental backups Monday through Saturday. A server fails on Thursday at 10:00 AM. Which sequence correctly restores the data?
Easy156A file server running Windows Server 2016 is critical for a department's daily operations. For the past two weeks, it has been crashing with a blue screen every 1–2 days. The IT team collects minidump files and opens the latest one in WinDbg. After running '!analyze -v', they obtain the following output: ``` DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1) An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high. This is usually caused by drivers using improper addresses. Arguments: Arg1: fffff80012345678, memory referenced Arg2: 0000000000000002, IRQL Arg3: 0000000000000000, value 0 = read operation, 1 = write operation Arg4: fffff80abcde1234, address which referenced memory Debugging Details: ... PROCESS_NAME: fileserver.exe SYMBOL_NAME: NetAdapterCx.sys!NetAdapterCxSetLinkState+0x1234 IMAGE_NAME: NetAdapterCx.sys ... ``` The server has 64GB ECC RAM, two Intel Xeon processors, and a Broadcom NetXtreme quad-port 10GbE NIC. The NIC driver was updated from version 7.12.6 to 7.14.8 two weeks ago as part of patch management. The BSODs started occurring immediately after that driver update; prior to the update, the server had been stable for over six months. The driver was obtained from the server manufacturer's support site and installed without error. The administrator wants to restore stability with minimal downtime and risk. Which action should the administrator take FIRST?
Hard157A server configured with a RAID 5 array and a hot spare experiences intermittent crashes under heavy disk I/O. A technician suspects a failing drive. Which of the following should the technician do FIRST?
Medium158Users report slow file server performance. The administrator suspects a single process is consuming excessive CPU and wants to analyse its threads and handles. Which tool should be used?
Medium159A mid-sized e-commerce company experienced a ransomware attack that encrypted all on-premises servers and their locally attached backup storage. The attack occurred on a Friday evening; the company was closed over the weekend. By Monday morning, the IT team discovered the encryption and found a ransom note demanding $500,000 in Bitcoin. The company has a disaster recovery plan that calls for restoring from daily tape backups stored offsite. However, the most recent offsite tape was taken home by a backup operator for the weekend and has not been returned. The tape contains full backups from Wednesday. The IT team has clean installation media and application software available. The company's RPO is 24 hours, and RTO is 48 hours. Management wants to minimize data loss and avoid paying the ransom. Based on this scenario, which of the following should the IT team do to recover the business operations?
Hard160A large financial services company must comply with federal regulations mandating quarterly disaster recovery tests. Their primary data center in New York hosts all trading applications, and a hot site in Chicago is maintained with real-time data replication via synchronous mirroring. During the last DR test, the IT team successfully failed over network and storage within 8 minutes, meeting the 15-minute RTO for connectivity. However, they encountered a major issue: the hot site's firewalls, intrusion detection systems, and application-level access controls were not configured to match the primary environment. The security team had to manually create firewall rules, update IDS signatures, and reconfigure access policies based on documentation, which took over 4 hours. As a result, the total system readiness exceeded 4.5 hours, causing a significant gap in trading operations. The regulatory auditor noted this deficiency and required a corrective action plan. The company must ensure that the next DR test achieves full operational readiness, including security controls, within the 15-minute RTO. The IT budget is already allocated for the current fiscal year, so large capital expenditures are not possible, but the team can leverage existing tools and automation. Which of the following is the BEST approach to address this issue?
Hard161A server experienced an unexpected power loss. After power is restored, the server boots successfully, but several critical services fail to start automatically. The administrator checks the system logs and finds errors indicating missing LUNs from a SAN. The SAN administrator confirms the SAN is online and the LUNs are assigned to the server's WWNs. The server uses FC HBAs. Which TWO steps should the administrator perform to diagnose the issue?
Medium162Refer to the exhibit. A web server is running on port 80, but users are unable to connect. The administrator has confirmed the web server service is running. The output of iptables -L is shown. What is the most likely reason for the connectivity issue?
Medium163A data center technician is troubleshooting a server that is overheating and shutting down intermittently. The server is a 2U rackmount with six fans at the front and a power supply with an integrated fan at the rear. The technician checks the ambient temperature (72°F) and verifies that the server intake temperature is normal. The server's system logs show 'CPU temperature threshold exceeded' before each shutdown. The technician has replaced the thermal paste on the CPU and reseated the heat sink, but the issue persists. Which of the following should the technician do NEXT?
Hard164A company wants to protect its Microsoft SQL Server database with a backup strategy that provides point-in-time recovery up to every 15 minutes. The database is critical and runs on a dedicated server. Which backup schedule should be implemented?
Easy165A small law firm has a single on-premises server running their case management software, email, and document storage. They perform a full backup each night at 11 PM to an external USB 4 TB drive, which is then stored on a shelf in the server room. The server room is located in the basement of their office building. Last week, an electrical fire started in the server room, completely destroying the server and the backup drive. The firm lost all data since the last backup, and it took two weeks to procure new hardware and restore from an older, off-site backup that was taken during a manual process three months ago. Their insurance company now requires a formal disaster recovery plan. The firm has a limited budget and minimal IT staff. They want to prevent data loss and minimize downtime in future disasters. What is the BEST course of action to improve their disaster recovery capabilities?
Easy166A company is expanding its data center to support a new four-node database cluster for a critical application requiring 99.999% uptime, meaning only minutes of downtime per year. Each server node has dual 1000W power supplies. The facility provides two independent power feeds from separate utility substations, each backed by its own online double-conversion UPS. There are four 20A/208V PDUs available, two per power feed. The design must ensure that the loss of any single power feed, any single UPS, or any single PDU does not cause any server to lose power or impact the cluster's availability. The servers are located in a single rack, and cabling must follow best practices for manageability and airflow. The IT architect is evaluating different power distribution strategies to meet these fault-tolerance requirements. Which of the following configurations achieves full redundancy with no single point of failure in the power path?
Hard167Refer to the exhibit. A technician is troubleshooting a server that is experiencing data corruption. What is the MOST likely cause?
Hard168To comply with company security policies, a server administrator must disable all unnecessary services on a newly deployed Windows Server 2019. The server will only act as a file server with no web hosting role. Which service should be disabled?
Easy169An organization's disaster recovery plan specifies an RPO of 4 hours. Their current backup schedule performs a full backup at midnight and incremental backups every 2 hours from 8:00 AM to 8:00 PM. A server failure occurs at 3:00 AM, and data created after 8:00 PM the previous day is permanently lost. Which of the following is the MOST likely reason?
Medium170Refer to the exhibit. A server administrator is reviewing security logs after a suspected brute-force attack on the SSH service. The following excerpt from /var/log/secure is displayed. Which security control would have been MOST effective in preventing the successful login?
Hard171You are a server engineer for a financial services firm. The company recently deployed a new HP ProLiant DL380 Gen10 server running Windows Server 2022 with SQL Server 2019. The server has 2 Intel Xeon Gold processors, 128GB RAM, and a Smart Array P408i-p controller managing two RAID 1 arrays: one for OS (two 300GB 10K SAS) and one for data (four 600GB 10K SAS). After one month, the OS array reports a predictive failure on one drive. You replace the drive via hot-swap, and the RAID controller rebuilds. However, the server now experiences random system crashes with Event ID 1001 (BugCheck) and the SQL database occasionally becomes corrupt requiring restore from backup. The server's RAM has been tested with HP's diagnostic tool and passed, and the CPU temperature is normal. The RAID controller log shows no errors during the rebuild but occasional 'Parity errors' logged before the drive replacement. Which of the following is the MOST likely cause of the current instability?
Hard172A server fails to complete POST and emits a series of beeps: two long, three short. According to the manufacturer's documentation, this beep code indicates a memory error. The server has eight DIMMs installed. Which of the following steps should the technician perform FIRST?
Easy173A server's performance degrades significantly during peak usage hours. Monitoring shows high memory utilization and consistently high disk I/O. Which of the following should the technician check FIRST?
Medium174An organization wants to test its disaster recovery plan with minimal disruption to business operations and minimal cost. The test should verify the plan's effectiveness by discussing scenarios. Which type of test should they perform?
Easy175During a security incident, a server is suspected to be compromised by malware. The incident response team needs to preserve evidence and minimize impact. Which TWO actions should be taken FIRST? (Select TWO.)
Easy176A server administrator is assembling a new high-performance server using a Supermicro X12 motherboard, two Intel Xeon Gold 5317 processors (LGA 4189 socket), and 16x 32GB DDR4-3200 ECC LRDIMMs for a total of 512GB of memory. The chassis has redundant 1600W power supplies. After assembling all components, the administrator powers on the server. All fans start spinning at full speed, and the front panel LEDs illuminate. However, the server does not POST, there are no beep codes, and no video output is displayed. The motherboard has a two-digit hexadecimal POST code LED display, which shows '00' and does not change. The motherboard manual states that code '00' indicates the CPU is not detected or has failed. The processors are confirmed to be the correct socket type and stepping as required by the motherboard. What should the technician do FIRST?
Medium177Refer to the exhibit. A Linux server started reporting I/O errors to its local disk. The administrator runs `dmesg` and sees the output shown. Which of the following is the MOST likely cause of the errors?
Hard178A company is creating a disaster recovery plan for its on-premises data center. Which THREE elements are essential to include in the DR plan? (Select THREE.)
Medium179A SQL Server database administrator wants to backup a large database (500 GB) with minimal impact on transaction log growth and recovery time. Which TWO backup strategies should the administrator implement? (Choose two.)
Medium180A technician is installing a new 2U server into an existing rack. The rack is fully populated with servers that use front-to-back airflow. The new server also uses front-to-back cooling. The technician notices gaps between some servers and several open rack units without equipment. To ensure optimal airflow and prevent potential thermal issues, which of the following actions should the technician take FIRST?
Medium181After an unexpected power outage, a server fails to boot and displays an error indicating a degraded RAID array. The server has a RAID 5 configuration with four disks. One disk has failed, but the hot spare did not automatically rebuild. The administrator needs to restore data availability as quickly as possible. Which action should the technician take FIRST?
Medium182Refer to the exhibit. A Linux server is reporting slow I/O on the root filesystem. Which of the following actions should the administrator take to resolve the immediate storage bottleneck?
Hard183A technician is installing a new server in a data center. To prevent electrostatic discharge (ESD) damage, which of the following should the technician do FIRST?
Easy184A company has a small virtualized environment with two ESXi 7.0 hosts (HostA and HostB) managed by vCenter Server. They use a shared iSCSI storage array for all VMs. The network consists of a single physical switch that connects the hosts, storage, and management traffic using VLANs. Yesterday, the switch failed and was replaced with an identical model. After restoring the configuration from a backup, all VMs on HostA are working normally, but all VMs on HostB show 'network disconnected' in the vSphere console. The VMs on HostB are still running, but they cannot communicate with any other device on the network. HostB itself is reachable via its management IP and can access the storage array. The administrator has verified that the physical cables are correct and the NICs are up on HostB. The VLAN configuration on the new switch was restored for the ports connecting HostB, but the issue persists. Which of the following actions should the administrator perform FIRST to restore connectivity?
Hard185A server has four memory slots on two channels (A and B). Currently, DIMM_A1 and DIMM_A2 are populated with 8 GB DDR4-2666 modules each. To maximize performance and capacity, which memory configuration should be added?
MediumOther domains
All SK0-005 exam domains
Frequently asked questions
- What does the scenario questions domain cover on the SK0-005 exam?
- scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 185 scenario questions questions in the SK0-005 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only scenario questions questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.