Courseiva
Back to CompTIA Server+ SK0-005 questions

Scenario-based practice

Performance-Based Questions (PBQs)

Practise CompTIA Server+ SK0-005 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
SK0-005
exam code
CompTIA
vendor

Scenario guide

How to approach performance-based questions (pbqs)

Performance-based questions drop you into a simulated CLI or lab environment and ask you to complete a real configuration task. On Cisco exams this means IOS commands in a terminal with a live topology. PBQs are worth more marks and appear first in the exam — get these right.

Quick answer

Performance-Based Questions (PBQs) questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related SK0-005 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediumScenario
Full question →

You are a server administrator at a mid-sized company that hosts its own on-premises Exchange server and file server. The infrastructure consists of three racks: Rack A contains the core switches and firewalls, Rack B contains the Exchange server (Dell PowerEdge R740) and the file server (HP ProLiant DL380 Gen10), and Rack C contains backup devices and a tape library. The data center cooling is provided by a raised-floor system with perforated tiles. Recently, the file server has been experiencing random shutdowns during peak usage hours (10 AM to 2 PM). The shutdowns are preceded by system event log warnings indicating that the CPU temperature has exceeded the threshold. The ambient temperature around the rack is 20°C (68°F) as measured by a handheld thermometer. Other servers in Rack B do not exhibit this behavior. The file server is a 2U server with two Xeon processors, 128 GB RAM, and six hot-swap SATA drives. It runs Windows Server 2019. The server has been in service for three years with no prior issues. The data center manager has noted that the perforated tiles are clear of obstructions. You have verified that the fans in the file server are spinning and the internal air filters are clean. Which of the following is the MOST likely cause of the overheating issue?

Question 2hardScenario
Full question →

A medium-sized company uses a backup strategy that includes a full backup every Sunday at 2:00 AM and differential backups Monday through Saturday at 2:00 AM. The backups are written to a network-attached storage (NAS) device. On Thursday morning, the company experiences a ransomware attack that encrypts all data on the file server, including the NAS. The administrator needs to restore the file server with minimal data loss. The last successful full backup was from the previous Sunday, and differential backups were successful on Monday, Tuesday, and Wednesday. However, Thursday's differential was not completed because the attack occurred before the scheduled time. The administrator attempts to restore using the Sunday full backup and Thursday's differential, but the restore fails because the differential backup on the NAS is also encrypted. Which of the following is the best course of action?

Question 3easyScenario
Full question →

A small accounting firm has a single server that hosts their client database and financial applications. The server is backed up nightly using a full backup to an external USB hard drive, which is stored on a shelf next to the server. Last month, a fire broke out in the office, completely destroying the server and the backup drive. The company lost all data since their last offsite backup, which was six months old because they occasionally took a copy home. The business owner wants to prevent such a catastrophic data loss in the future but is concerned about cost and complexity. They have a limited IT budget and no dedicated IT staff. The firm operates 9-5 Monday to Friday, and can tolerate up to 24 hours of downtime and up to one day of data loss. After the fire, they had to rebuild their client records from paper files, which took weeks. The owner realizes the importance of an offsite backup routine but cannot afford an expensive cloud service or a second server. The firm's internet connection is a basic DSL line with limited upload bandwidth, making large cloud backups slow. The server has a single internal drive with enough free space to store additional copies. Which of the following backup strategies would best meet the firm’s recovery objectives while minimizing cost and complexity?

Question 4mediumScenario
Full question →

A regional hospital operates two data centers located 10 miles apart, with synchronous replication of critical patient record systems between them. The replication ensures that any write to the primary storage is immediately mirrored to the secondary site. The hospital also maintains weekly full backups to LTO-8 tapes, which are stored in a fireproof safe at an offsite warehouse 30 miles away. The IT team has not implemented storage snapshots or continuous data protection due to budget constraints. Last week, a ransomware attack encrypted all files on the primary site. The replication process promptly mirrored the encrypted data to the secondary site, rendering both copies inaccessible. The attackers demanded $500,000 in Bitcoin. The hospital's disaster recovery plan specifies an RPO of 1 hour and an RTO of 4 hours. The IT director must now choose a restoration strategy that minimizes data loss and downtime while ensuring a clean, malware-free environment. The backup tapes are confirmed to be unencrypted and free of ransomware. Which of the following actions should the IT director take first?

A company has a small virtualized environment with two ESXi 7.0 hosts (HostA and HostB) managed by vCenter Server. They use a shared iSCSI storage array for all VMs. The network consists of a single physical switch that connects the hosts, storage, and management traffic using VLANs. Yesterday, the switch failed and was replaced with an identical model. After restoring the configuration from a backup, all VMs on HostA are working normally, but all VMs on HostB show 'network disconnected' in the vSphere console. The VMs on HostB are still running, but they cannot communicate with any other device on the network. HostB itself is reachable via its management IP and can access the storage array. The administrator has verified that the physical cables are correct and the NICs are up on HostB. The VLAN configuration on the new switch was restored for the ports connecting HostB, but the issue persists. Which of the following actions should the administrator perform FIRST to restore connectivity?

Question 6hardScenario
Full question →

A corporation's backup strategy currently involves a weekly full backup every Saturday night and daily differential backups Monday through Friday. The company has a 5 TB dataset with a daily change rate of about 10%. The full backup takes 12 hours and runs into Monday morning, impacting production performance. The backup window is from 10 PM to 6 AM. The company requires faster backups that can complete within the window, and they also want an offsite copy of the backups for disaster recovery. The existing backup server has direct-attached disk storage and a tape library. The network bandwidth to the offsite location is limited to 100 Mbps. The administrator is evaluating changes to the backup methodology and infrastructure to meet these requirements. Which of the following solutions best addresses the speed and offsite requirements?

Question 7hardScenario
Full question →

A small business relies on a tower server that acts as a file and print server for 15 employees. The server has a single Intel Xeon E-2300 series processor, four 16GB DDR4 ECC RDIMMs installed in dual-channel configuration, and two 2TB 7200 RPM SATA hard drives in a hardware RAID 1 mirror. The power supply unit (PSU) is a 500W 80+ Bronze unit that is about four years old. Recently, the server has started experiencing random, intermittent crashes resulting in a blue screen, typically during periods of heavy disk I/O, such as when multiple users access large files. Event Viewer logs show occasional corrected memory errors (ECC events) but no uncorrected errors. The administrator runs MemTest86+ on all four DIMMs for multiple passes, and no errors are detected. The server room ambient temperature is normal, and all fans are operating. The crashes are becoming more frequent. Which of the following actions would MOST likely resolve the underlying issue?

Question 8mediumScenario
Full question →

An administrator is monitoring a server that has a hardware RAID 5 array consisting of four 2 TB disks. The RAID controller's management software reports that one disk has a status of 'Pred Fail' (predictive failure). The array also has a dedicated hot spare disk already installed and set up. The array is still fully functional with no data loss, but the 'Pred Fail' warning indicates the disk is likely to fail soon. The server is a production database server that cannot be taken offline except for scheduled maintenance windows, which are not until the following weekend. The administrator needs to ensure data integrity and avoid any risk of downtime or data loss while waiting for the replacement. Which immediate action should the administrator take?

Question 9hardScenario
Full question →

You are a server engineer for a financial services firm. The company recently deployed a new HP ProLiant DL380 Gen10 server running Windows Server 2022 with SQL Server 2019. The server has 2 Intel Xeon Gold processors, 128GB RAM, and a Smart Array P408i-p controller managing two RAID 1 arrays: one for OS (two 300GB 10K SAS) and one for data (four 600GB 10K SAS). After one month, the OS array reports a predictive failure on one drive. You replace the drive via hot-swap, and the RAID controller rebuilds. However, the server now experiences random system crashes with Event ID 1001 (BugCheck) and the SQL database occasionally becomes corrupt requiring restore from backup. The server's RAM has been tested with HP's diagnostic tool and passed, and the CPU temperature is normal. The RAID controller log shows no errors during the rebuild but occasional 'Parity errors' logged before the drive replacement. Which of the following is the MOST likely cause of the current instability?

Question 10hardScenario
Full question →

A data center technician is troubleshooting a server that is overheating and shutting down intermittently. The server is a 2U rackmount with six fans at the front and a power supply with an integrated fan at the rear. The technician checks the ambient temperature (72°F) and verifies that the server intake temperature is normal. The server's system logs show 'CPU temperature threshold exceeded' before each shutdown. The technician has replaced the thermal paste on the CPU and reseated the heat sink, but the issue persists. Which of the following should the technician do NEXT?

Question 11mediumScenario
Full question →

A server administrator receives reports that a production server is shutting down unexpectedly after running for several hours. The server is a 2U rackmount unit located in a data center with proper ambient cooling (20°C/68°F). The server has redundant power supplies connected to separate PDUs and no power anomalies are reported. The administrator checks the operating system event logs and finds a critical log entry: 'The system was shut down due to a thermal event.' However, the CPU temperature logs show that the CPU was at 47°C at the time of shutdown, and the chassis inlet temperature was 23°C. The server's internal fans are running at high speed and are clearly audible. The administrator suspects a thermal issue but is unsure why the CPU is not showing high temperature. The server has a baseboard management controller (BMC) that monitors various sensors. Which of the following components should the administrator investigate FIRST to identify the likely cause of the shutdown?

Question 12mediumScenario
Full question →

A medium-sized business runs a critical internal application on a single physical server running Windows Server 2019. The application is memory-intensive, often using up to 24 GB out of 32 GB RAM during peak hours. Over the past week, the server has experienced three unexpected reboots, each occurring during peak load. The server is not part of a cluster, and all data is stored on local disks. You have checked the Windows System event log and found Event ID 41 (Kernel-Power) indicating an unexpected shutdown. There are no related critical errors in the Application log. You have also reviewed the server's firmware logs and found multiple corrected memory errors (ECC) over the last month, with an increase in frequency just before each crash. The server is under warranty, and the hardware vendor's diagnostic tools report a failing memory module in DIMM slot A1. The vendor has recommended replacing the faulty DIMM immediately. However, the server is currently processing critical end-of-quarter financial reports that cannot be interrupted for at least 6 hours. Which of the following is the BEST course of action to minimize risk of data loss and downtime until a planned maintenance window?

Question 13hardScenario
Full question →

A company is expanding its data center to support a new four-node database cluster for a critical application requiring 99.999% uptime, meaning only minutes of downtime per year. Each server node has dual 1000W power supplies. The facility provides two independent power feeds from separate utility substations, each backed by its own online double-conversion UPS. There are four 20A/208V PDUs available, two per power feed. The design must ensure that the loss of any single power feed, any single UPS, or any single PDU does not cause any server to lose power or impact the cluster's availability. The servers are located in a single rack, and cabling must follow best practices for manageability and airflow. The IT architect is evaluating different power distribution strategies to meet these fault-tolerance requirements. Which of the following configurations achieves full redundancy with no single point of failure in the power path?

Question 14mediumScenario
Full question →

A server administrator is assembling a new high-performance server using a Supermicro X12 motherboard, two Intel Xeon Gold 5317 processors (LGA 4189 socket), and 16x 32GB DDR4-3200 ECC LRDIMMs for a total of 512GB of memory. The chassis has redundant 1600W power supplies. After assembling all components, the administrator powers on the server. All fans start spinning at full speed, and the front panel LEDs illuminate. However, the server does not POST, there are no beep codes, and no video output is displayed. The motherboard has a two-digit hexadecimal POST code LED display, which shows '00' and does not change. The motherboard manual states that code '00' indicates the CPU is not detected or has failed. The processors are confirmed to be the correct socket type and stepping as required by the motherboard. What should the technician do FIRST?

Question 15hardScenario
Full question →

You are the lead server administrator for a mid-sized e-commerce company. The web application is hosted on a farm of four Linux servers running Apache, fronted by a hardware load balancer. The load balancer currently uses a round-robin algorithm. Recently, the customer support team has received numerous complaints about slow page load times and occasional timeouts during checkout. You log into the server monitoring console and observe that one of the web servers, web03, has a CPU utilization consistently above 95%, while the other three servers are at around 30-40%. You connect via SSH to web03 and run the 'top' command, identifying a process named 'imagick' consuming 99% CPU. Further investigation reveals that this process is related to image resizing for product thumbnails, and it appears to have entered an infinite loop due to a malformed image file. Meanwhile, the load balancer continues to send requests to all servers equally, including the overloaded web03, causing some requests to time out. You need to restore performance immediately and prevent recurrence. Which of the following actions should you take?

Question 16easyScenario
Full question →

A small law firm has a single Windows Server 2016 Essentials server that functions as a domain controller and file server. After a sudden power outage over the weekend, the server does not boot normally. Instead, it displays a black screen with the message: 'BOOTMGR is missing. Press Ctrl+Alt+Del to restart.' The IT support specialist arrives on Monday morning to find the server in this state. The firm's operations are at a standstill because all case files and email archives are inaccessible. The specialist has access to the Windows Server 2016 installation media and a recent system state backup stored on an external drive. The server hardware passed POST, and all disks are detected in the BIOS. The specialist needs to restore the server's ability to boot into Windows as quickly as possible, with minimal risk to existing data. Which of the following procedures should the specialist perform FIRST?

Question 17hardScenario
Full question →

A company runs a popular public-facing e-commerce website hosted on a farm of five Windows Server 2019 web servers behind a hardware load balancer. Recently, users have been reporting intermittent '503 Service Unavailable' errors during peak shopping hours. The administrator checks the load balancer and finds that all servers are marked as healthy with low CPU and memory usage. However, when inspecting a sample server, the administrator notices a large number of TCP connections in the TIME_WAIT state, consuming all available ephemeral ports. The application is ASP.NET based and uses IIS. The server configuration is as follows: Windows Server 2019 Standard, 4 vCPUs, 16 GB RAM, default TCP/IP settings. The administrator needs to resolve the connectivity issues without making changes to the application code or altering the network architecture. Which of the following actions should the administrator take to fix the problem PERMANENTLY?

Question 18easyScenario
Full question →

A small law firm relies on a single server that hosts a document management system and email. The server is backed up nightly using differential backups to an external USB hard drive that remains connected to the server. One Monday morning, the office manager finds all files encrypted and a ransom note on the screen. The server’s event logs indicate that the encryption began at 2:00 AM on Saturday. The firm’s offsite backup policy rotates two sets of tapes, and the most recent set was taken offsite on Friday evening and is stored in a bank safe deposit box. The USB backup drive, still attached to the server, shows its files also encrypted. The firm does not have a cloud backup service for the server. The office manager wants to restore operations as quickly as possible with minimal data loss and zero risk of reinfection. What is the BEST course of action?

Question 19easyScenario
Full question →

A junior administrator is managing a Linux server used by a development team. The root filesystem (/) has reached 98% capacity, causing the system to slow down and some applications to fail. The server has an LVM volume group with 20 GB of free space, but the root logical volume is 50 GB with an ext4 filesystem. The administrator needs to free space quickly and safely without rebooting or adding new disks. They log in via SSH and want to identify where the large files are and then take action. There are concerns about accidentally deleting critical system files or logs that might be needed for auditing. The server has the following typical directories: /var (with logs), /home (user files), /opt (application files), /tmp. Which of the following sequences of actions is the most appropriate to resolve the issue?

Question 20hardScenario
Full question →

A mid-sized e-commerce company experienced a ransomware attack that encrypted all on-premises servers and their locally attached backup storage. The attack occurred on a Friday evening; the company was closed over the weekend. By Monday morning, the IT team discovered the encryption and found a ransom note demanding $500,000 in Bitcoin. The company has a disaster recovery plan that calls for restoring from daily tape backups stored offsite. However, the most recent offsite tape was taken home by a backup operator for the weekend and has not been returned. The tape contains full backups from Wednesday. The IT team has clean installation media and application software available. The company's RPO is 24 hours, and RTO is 48 hours. Management wants to minimize data loss and avoid paying the ransom. Based on this scenario, which of the following should the IT team do to recover the business operations?

These SK0-005 practice questions are part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style SK0-005 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.