All practice questions

3551 questions

Question 1161Question

An IT administrator is configuring Windows 11 Pro workstations located in a computer lab to prevent standard user accounts from generating credential prompts or asking for administrative credentials when running setup programs. The objective is to automatically reject elevation requests from standard users without user intervention. Which User Account Control (UAC) security option in Local Security Policy should be configured to meet this requirement?

Show answer & explanation

Answer: User Account Control: Behavior of the elevation prompt for standard users set to Automatically deny elevation requests

Answer

Configure 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' in Local Security Policy (secpol.msc).
Setting 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' prevents Windows from displaying an administrative credential prompt to non-admin users, immediately returning an access denied message whenever privilege elevation is requested.

Step-by-Step Solution

1
Identify the goal of suppressing credential prompts for standard users.
Recognize that standard users should be automatically denied privilege elevation rather than prompting for administrator credentials.
By default, UAC prompts standard users for an administrator password (Prompt for credentials).
2
Locate the relevant security policy setting under Security Options in secpol.msc.
Identify 'User Account Control: Behavior of the elevation prompt for standard users'.
This specific policy explicitly controls how UAC responds when a standard user account attempts an action requiring administrative privileges.
3
Select the policy value that automatically rejects requests.
Set the value to 'Automatically deny elevation requests'.
This setting directly blocks elevation attempts without presenting a credential entry window to the standard user.

Key Concept

User Account Control (UAC) Local Security Policy Settings
Estimated Time:1m 15s
Question 1162Question

A desktop technician is performing a clean installation of Windows 11 on a newly assembled workstation equipped with a brand-new, unformatted NVMe solid-state drive. What is the correct sequence of steps the technician must follow from first to last to complete the operating system installation process?

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct chronological sequence is: 1) Boot from USB media via UEFI mode, 2) Select unallocated space to create default partitions, 3) Copy files and install features, and 4) Complete the Out-of-Box Experience (OOBE) setup.
Performing a clean operating system installation follows a strict sequence: first, boot the hardware using bootable installation media in UEFI mode; second, initialize and select the unallocated storage drive so Windows Setup can partition it properly; third, allow the setup program to copy and expand installation files onto the drive and perform a system reboot; finally, complete the initial user configuration and customization in the Out-of-Box Experience (OOBE) phase.

Step-by-Step Solution

1
Boot from flash media
The Windows Preinstallation Environment (WinPE) setup interface loads into memory.
The system cannot install an OS onto a blank drive without booting from an external installation source first.
2
Partition target storage
System creates required partition structures (EFI system partition, MSR, and primary NTFS partition).
Windows 11 requires a GUID Partition Table (GPT) disk layout and formatted file system structure before file extraction.
3
Perform file installation and reboot
Core OS binaries are copied to disk and the system reboots into the installed OS image.
Installation files must be expanded and written to local storage before user-level configuration can occur.
4
Configure Out-of-Box Experience (OOBE)
Initial user account, region, internet connection, and system privacy settings are established.
OOBE finalizes the personalization and initial user setup phase after the primary installation phase completes.

Key Concept

Standard Clean OS Installation Workflow
Estimated Time:1m 30s
Question 1163Question

A helpdesk technician is reviewing a security ticket submitted by a finance manager. The manager received a text message on her mobile phone appearing to come from the company's banking vendor, warning that the organization's payroll account would be locked within 30 minutes due to unverified compliance documentation. The message contained a hyperlink prompting her to log in immediately. Which of the following social engineering attack vectors describes this initial contact method?

Show answer & explanation

Answer: Smishing

Answer

The correct attack vector is smishing, as it specifically utilizes SMS text messaging on mobile devices to deliver deceptive phishing links.
Smishing refers specifically to phishing attacks conducted over Short Message Service (SMS) text messages. The scenario describes an urgent text message sent to a cellular device containing a fraudulent link designed to harvest banking credentials.

Step-by-Step Solution

1
Analyze the delivery medium described in the scenario.
The initial contact occurred via a text message sent to a mobile phone.
Identifying the transmission channel is necessary to distinguish between social engineering classifications.
2
Evaluate threat classification terminology based on delivery medium.
Phishing over Short Message Service (SMS) is classified as smishing.
Standard security taxonomy distinguishes SMS-based attacks (smishing) from voice-based (vishing) and email-based (phishing/spear phishing) attacks.

Key Concept

Social Engineering Delivery Vectors (Smishing vs. Vishing vs. Phishing)
Question 1164Question

Match each social engineering threat or attack vector on the left with its corresponding attack description on the right.

Click a left item, then click its matching right item

Items

Pretexting
Shoulder Surfing
Watering Hole Attack
Typosquatting

Matches

Show answer & explanation

Answer

Pretexting matches the creation of a fabricated scenario by an auditor impersonator; Shoulder Surfing matches visual observation of passwords; Watering Hole Attack matches compromising a frequently visited industry website; Typosquatting matches registering misspelled domain names.
Each attack vector is matched to its defining characteristic: Pretexting involves creating a believable false context or identity; Shoulder Surfing involves physical line-of-sight observation; Watering Hole Attacks infect legitimate sites known to be frequented by targets; Typosquatting exploits user mistyping in web addresses.

Step-by-Step Solution

1
Analyze the social engineering techniques involving deceptive scenarios.
Pretexting is identified as creating an invented scenario (a pretext) such as posing as an auditor to gain trust and credentials.
Pretexting specifically centers on creating a persona and scenario to manipulate the victim.
2
Analyze physical observation techniques.
Shoulder surfing is identified as visually observing a victim entering sensitive information like PINs or passwords.
Direct line-of-sight monitoring of screens or keypads defines shoulder surfing.
3
Analyze website-focused attack vectors.
Watering hole attacks compromise trusted industry websites frequented by targets, while typosquatting targets mistyped domain names.
Distinguishing between strategic site compromise (watering hole) and domain registration tricks (typosquatting) correctly pairs the web-based vectors.

Key Concept

Social Engineering Tactics and Attack Vector Classification
Question 1165Question

While working on a company laptop in a public cafe, a remote employee notices an unfamiliar individual standing nearby and looking directly over their shoulder to observe credentials as they are typed. Which of the following social engineering threat types is occurring in this scenario?

Show answer & explanation

Answer: Shoulder surfing

Answer

Shoulder surfing
The correct answer is shoulder surfing because the attacker is visually monitoring the user's screen and keyboard in a public area to capture sensitive login details.

Step-by-Step Solution

1
Analyze the attack vector described in the scenario.
The attack involves direct physical line-of-sight observation of an employee's computer screen and keyboard in a public setting.
Identifying the method of observation narrows down the specific social engineering threat category.
2
Match the observed behavior with standard social engineering terminology.
Directly watching someone enter sensitive information over their shoulder or from a nearby vantage point is classified as shoulder surfing.
Understanding security definitions allows proper classification and mitigation.

Key Concept

Shoulder Surfing
Estimated Time:45s
Question 1166Question

Match each physical security control mechanism on the left with its primary protective function or implementation purpose on the right.

Click a left item, then click its matching right item

Items

Biometric Scanner
Cable Lock
Industrial Cross-Cut Shredder
Proximity Card Reader

Matches

Show answer & explanation

Answer

The correct matches pair Biometric Scanner with verifying identity using unique physical traits, Cable Lock with securing hardware to stationary fixtures, Industrial Cross-Cut Shredder with destroying sensitive paper and optical media, and Proximity Card Reader with granting access via contactless token detection.
Each physical security control serves a specific protective purpose: Biometric scanners use physiological attributes to verify identity, cable locks physically anchor hardware to prevent theft, shredders render physical media unreadable to prevent dumpster diving, and proximity readers validate RFID access tokens.

Step-by-Step Solution

1
Identify the primary function of a Biometric Scanner
Matches with verifying identity via unique physical traits.
Biometrics rely on biological characteristics such as fingerprints or retina scans for authentication.
2
Identify the primary function of a Cable Lock
Matches with securing hardware to stationary fixtures.
Cable locks physically tie down equipment using hardened steel cables connected to security slots.
3
Identify the primary function of an Industrial Cross-Cut Shredder
Matches with destroying paper and media to prevent dumpster diving.
Shredding ensures physical documents and media cannot be reconstructed by attackers.
4
Identify the primary function of a Proximity Card Reader
Matches with granting physical access based on contactless token detection.
Proximity card readers detect RFID/NFC signals emitted from employee access badges.

Key Concept

Physical Security Controls and Functions
Estimated Time:1m 30s
Question 1167Question

A remote employee connects a Windows 11 laptop to a home Wi-Fi network. The laptop successfully receives a local IP address from the home router via DHCP, and the user can reach public websites using raw IPv4 addresses (such as http://1.1.1.1). However, web browsing fails when entering standard web domain names. Inspection of the Wi-Fi network adapter IPv4 properties reveals that static DNS server addresses from the corporate office are still configured. Which configuration change in the TCP/IPv4 properties will resolve the issue and allow the client to resolve domain names dynamically?

Show answer & explanation

Answer: Select 'Obtain DNS server address automatically' in the adapter IPv4 properties.

Answer

Select 'Obtain DNS server address automatically' in the adapter IPv4 properties.
Selecting 'Obtain DNS server address automatically' allows the client network adapter to receive functional local DNS server information directly from the local DHCP server, restoring domain name resolution without affecting dynamic IP address assignment.

Step-by-Step Solution

1
Analyze the symptoms described in the scenario.
Identified that network layer (IP) connectivity works because raw IPv4 address navigation functions, but application/name resolution fails due to unreachable static corporate DNS entries.
When a client moves from a corporate environment to a home network, hardcoded internal DNS server addresses remain unreachable, preventing DNS lookup queries from resolving hostnames to IP addresses.
2
Evaluate the TCP/IPv4 properties options.
Configuring the adapter to 'Obtain DNS server address automatically' enables DHCP to supply the local router's DNS settings.
This removes the static override and allows DNS requests to be answered by the ISP or home router's DNS service.

Key Concept

Windows Client IPv4 DNS Configuration and DHCP Overrides
Question 1168Question

Users across a enterprise mobile deployment report that a custom line-of-business application on their Android devices regularly freezes and stops responding during large background database synchronizations. Operating system performance monitoring indicates high memory usage tied to accumulated temporary sync files. A device restart resolves the sluggishness for only a few minutes before the sync process slows the app down again. The technician needs to resolve the performance degradation while strictly preserving the user's custom settings and local offline data files. Which of the following actions should the technician perform FIRST?

Show answer & explanation

Answer: Force stop the application and clear the application cache in the OS app settings menu.

Answer

Force stopping the application and clearing its application cache from the Android settings menu is the correct first step.
Force stopping the app and clearing its cache is the proper least-invasive troubleshooting step for application freezing caused by temporary file bloat. Clearing the cache removes temporary transaction logs causing performance bottlenecks while preserving user account settings, offline databases, and application preferences.

Step-by-Step Solution

1
Analyze the symptoms and constraints
The issue is isolated to excessive temporary sync files causing memory bloat; user settings and offline files must be preserved.
Troubleshooting methodology requires selecting the least invasive action that targets the root cause.
2
Differentiate between mobile application cache and application data
Clearing cache targets temporary files only, whereas clearing data resets all user preferences and local database files.
The scenario explicitly mandates preserving custom settings and local offline data files.
3
Apply the least invasive troubleshooting step
Force stopping the hung process and clearing its cache purges temporary background data while keeping user configurations intact.
This resolves background sync performance bottlenecks without requiring app re-enrollment or data restoration.

Key Concept

Least-Invasive Mobile App Performance Remediation (Cache vs. Data)
Estimated Time:2m 0s
Question 1169Question

A technician is installing a new wireless access point in a small home office that lacks a centralized RADIUS authentication server. The client requires a wireless security configuration that utilizes Advanced Encryption Standard (AES) for data privacy while authenticating users via a shared passphrase. Which of the following wireless security standards should the technician select?

Show answer & explanation

Answer: WPA2-Personal

Answer

WPA2-Personal is the correct security standard because it uses AES encryption and authenticates devices via a pre-shared key without requiring a RADIUS server.
WPA2-Personal utilizes AES encryption (CCMP) to secure wireless communications and uses a pre-shared key (PSK) for authentication, meeting the requirement for AES without needing a centralized RADIUS server.

Step-by-Step Solution

1
Analyze environment authentication constraints
No RADIUS server is present, which rules out enterprise 802.1X solutions.
Enterprise wireless modes require centralized authentication services like RADIUS.
2
Evaluate encryption protocol requirement
The requirement specifies AES (Advanced Encryption Standard).
Legacy protocols like WEP (RC4) and WPA-TKIP do not utilize AES.
3
Select the appropriate security protocol
WPA2-Personal fulfills both requirements by combining CCMP/AES encryption with passphrase-based PSK authentication.
It provides strong encryption without relying on external authentication infrastructure.

Key Concept

Wireless Encryption and Authentication (Personal vs. Enterprise)
Question 1170Question

A network administrator is troubleshooting an ultraportable corporate laptop equipped with an organic light-emitting diode (OLED) screen. The computer boots properly, and video output displays fine on an external desktop monitor via DisplayPort, but the internal laptop screen remains completely black. A junior technician proposes ordering a replacement high-voltage backlight inverter board. Which of the following best explains why this proposed repair is invalid?

Show answer & explanation

Answer: OLED panels generate their own illumination per pixel and do not use a backlight inverter board.

Answer

OLED panels generate their own illumination per pixel and do not use a backlight inverter board.
OLED (Organic Light-Emitting Diode) displays feature self-emissive pixels that produce their own light directly. Unlike traditional CCFL-backlit LCD monitors, OLED screens do not use a separate backlight unit or a high-voltage inverter board. Therefore, recommending an inverter board replacement for an OLED panel is invalid because that physical component is not present in OLED display architecture.

Step-by-Step Solution

1
Analyze the hardware environment and symptoms.
The laptop uses an OLED screen; external display output functions correctly, isolating the issue to internal panel hardware.
Identifying the display technology type isolates physical component dependencies.
2
Evaluate the underlying architecture of OLED displays.
OLED pixels emit light individually when electric current is applied, eliminating the need for a CCFL backlight or inverter board.
Inverters are exclusively required for legacy LCD screens that utilize Cold Cathode Fluorescent Lamp (CCFL) backlighting.
3
Evaluate the proposed resolution.
Recommending an inverter board replacement for an OLED screen is invalid because the component does not exist in OLED hardware.
Accurate component diagnosis prevents unnecessary downtime and ordering incompatible parts.

Key Concept

OLED display technology vs. legacy LCD backlighting architecture
Estimated Time:1m 15s
Question 1171Question

A user reports that a corporate communication app frequently freezes and becomes unresponsive on their Android smartphone. All other apps and network connectivity on the device are functioning normally. Following the least-invasive-first troubleshooting methodology, which of the following actions should the technician take FIRST?

Show answer & explanation

Answer: Force stop the app and clear the application cache.

Answer

Force stop the app and clear the application cache.
Force stopping the app and clearing its cache targets the specific problematic application process and its temporary cached files without wiping persistent user data or modifying overall system settings. This follows the standard CompTIA least-invasive-first troubleshooting principle.

Step-by-Step Solution

1
Isolate the issue scope.
Since only one application is freezing while other apps work properly, the issue is localized to that specific app's cached state or active process.
System-wide actions are unnecessary when the failure is limited to a single application.
2
Apply the least invasive troubleshooting step.
Force stopping the application terminates hung background processes, and clearing the app cache removes temporary corrupted data.
This resolves app stability issues quickly without deleting persistent user credentials or resetting the entire device.

Key Concept

Least-invasive mobile application troubleshooting methodology
Estimated Time:1m 15s
Question 1172Question

A system administrator is managing a remote macOS workstation over an SSH connection. The administrator needs to perform two tasks from the terminal: initiate an immediate system backup using the built-in macOS backup framework and search for specific configuration files by querying the system's Spotlight metadata index. Which of the following native command-line utilities should the administrator execute? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Use the tmutil command to control and initiate Time Machine backups.; Use the mdfind command to search files using the native Spotlight metadata index.

Answer

The administrator should use the tmutil utility to initiate Time Machine backups and the mdfind utility to search the Spotlight metadata index from the command line.
The tmutil utility is the native macOS command-line utility used to trigger and manage Time Machine backups over a shell session. The mdfind command is the native CLI utility that queries the macOS Spotlight search engine metadata index to locate files quickly without searching the full file system linearly.

Step-by-Step Solution

1
Identify the command-line utility for managing macOS Time Machine features.
Determine that tmutil is the native CLI tool for Time Machine.
macOS includes the tmutil command-line tool to allow administrators to start backups, examine snapshots, and adjust backup settings over remote terminal sessions.
2
Identify the command-line interface for querying Spotlight metadata.
Determine that mdfind is the native CLI search tool for Spotlight.
The mdfind utility queries the Spotlight index database directly from the terminal prompt to locate files matching specified metadata criteria.

Key Concept

macOS Native Command-Line Features and Utilities (tmutil and mdfind)
Question 1173Question

Match each administrative maintenance scenario to the correct Windows Control Panel utility used to perform the configuration.

Click a left item, then click its matching right item

Items

Configuring database driver connections and Data Source Names (DSNs) for a legacy 32-bit enterprise accounting client.
Rebuilding the system search catalog, specifying custom file extension indexing rules, and toggling full-text content search.
Viewing, modifying, or removing stored Windows Vault authentication tokens and saved domain/network share credentials.
Managing offline network folder cache settings, viewing file synchronization logs, and resolving file version conflicts.

Matches

Show answer & explanation

Answer

The correct pairings are: 32-bit database driver configuration matches ODBC Data Sources; search catalog and file content indexing matches Indexing Options; managing vault network credentials matches Credential Manager; and managing offline folder conflicts matches Sync Center.
Each Control Panel utility performs a distinct system management role: ODBC Data Sources manages database connection DSNs; Indexing Options controls search scope, rebuilds, and file content parsing; Credential Manager oversees saved network and web authentication tokens; and Sync Center administers offline network files and synchronization conflict resolution.

Step-by-Step Solution

1
Analyze the database configuration requirement.
Connecting legacy 32-bit applications to databases via DSNs requires the ODBC Data Sources applet.
ODBC (Open Database Connectivity) is the standard Windows interface for database connectivity management.
2
Analyze the search catalog and file extension requirement.
Configuring search behavior, file content indexing, and rebuilding catalogs is handled by Indexing Options.
Indexing Options directly controls Windows Search service targets and file property vs. content search rules.
3
Analyze stored authentication credentials.
Viewing and removing cached network share and web login tokens requires Credential Manager.
Credential Manager is the Windows Control Panel applet dedicated to managing saved Windows and Web credentials.
4
Analyze offline file cached paths and conflict resolution.
Handling Offline Files status and synchronization conflicts is performed in Sync Center.
Sync Center provides centralized control over network share caching, sync schedules, and conflict logs.

Key Concept

Windows Control Panel Administrative Utilities
Question 1174Question

A security engineer is hardening a pool of shared workstation computers running Windows 11 Enterprise. To mitigate insider threats, management mandates that standard users must never be allowed to elevate privileges or be presented with an administrator login prompt when executing unauthorized software. Which Security Options policy setting within the Security Settings node should the engineer configure to fulfill this requirement?

Show answer & explanation

Answer: Set 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests'.

Answer

Set 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests'.
Configuring 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' ensures that whenever an application attempts to run with administrative privileges from a standard user account, Windows immediately returns a permission denied error without prompting for administrator credentials.

Step-by-Step Solution

1
Identify the security goal in the scenario.
Standard users must be prevented from seeing or attempting administrative credential prompts upon elevation requests.
Security hardening requires blocking privilege escalation vectors entirely for standard user sessions.
2
Evaluate the User Account Control security policies related to standard user behavior.
The setting 'User Account Control: Behavior of the elevation prompt for standard users' controls prompt behavior.
Configuring this setting to 'Automatically deny elevation requests' enforces an immediate access denied error when standard users try running elevated operations.
3
Distinguish correct policy settings from unrelated file permissions and edition features.
NTFS permission changes or Control Panel applet modifications do not manage UAC elevation prompt policies.
UAC policies specifically dictate OS elevation consent and credential request behaviors.

Key Concept

User Account Control Security Policy Elevation Settings
Question 1175Question

A technician is troubleshooting a custom desktop PC that shuts down immediately after the power button is pressed. The internal fans spin for less than a second, the power LED blinks once, and the system completely loses power. Pressing the power button again does nothing until the power supply's rocker switch is toggled off and on. Which of the following actions should the technician perform first to isolate the underlying cause of this issue? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Disconnect non-essential expansion cards, internal drives, and front-panel USB headers to test for a short circuit tripping PSU protection.; Test the power supply output voltages using a dedicated PSU tester or multimeter to verify rail stability.

Answer

The technician should disconnect non-essential expansion cards and storage drives to isolate short circuits, and test the power supply output voltages using a power supply tester or multimeter.
The correct diagnostic actions involve isolating potential hardware short circuits by disconnecting non-essential peripherals and testing the power supply's voltage rails with a multimeter or dedicated tester. An instant shutdown where fans briefly turn on indicates a power supply short-circuit or over-current protection trip.

Step-by-Step Solution

1
Analyze the symptoms presented by the system.
The immediate power-off behavior (fans spinning briefly then shutting off) indicates a power supply protection mechanism (Over-Current Protection or Short-Circuit Protection) being triggered before POST.
Modern power supplies automatically shut off power when a short circuit or severe rail drop occurs, requiring a power cycle to reset.
2
Isolate potential short circuits from connected peripherals and internal hardware.
Disconnecting extra storage drives, expansion cards, and front USB connectors helps confirm whether an auxiliary hardware component is shorting a power line.
Minimizing system hardware identifies if the core platform (PSU, motherboard, CPU) is functional.
3
Verify the integrity of the power supply unit output.
Measuring output voltage rails (+12V, +5V, +3.3V) with a tester or multimeter determines if the PSU itself is defective.
A failing power supply with degraded capacitors will fail to maintain regulated voltages, causing instant thermal or voltage cutoffs.

Key Concept

Power supply unit (PSU) protection mechanisms and hardware short circuit isolation procedures
Question 1176Question

A cybersecurity technician is reviewing various security incident reports across an enterprise network. Match each threat type or social engineering vector on the left to its corresponding real-world incident description on the right.

Click a left item, then click its matching right item

Items

Typosquatting
Dumpster Diving
Logic Bomb
Smishing

Matches

Show answer & explanation

Answer

Typosquatting corresponds to registering lookalike web domains to exploit typing mistakes. Dumpster Diving corresponds to searching physical waste bins for un-shredded internal documents. Logic Bomb corresponds to dormant malicious code designed to execute upon specific system events or triggers. Smishing corresponds to using deceptive SMS text messages for phishing attacks.
Each attack vector accurately aligns with its defining operation: Typosquatting exploits browser address mistyping using lookalike domains; Dumpster Diving extracts physical papers from refuse areas; Logic Bombs run code conditionally upon specified triggers; and Smishing delivers phishing lures via mobile SMS messages.

Step-by-Step Solution

1
Analyze the attack vectors to distinguish digital communication vectors from physical vectors and program logic threats.
Identify physical data retrieval (waste inspection), mobile messaging (SMS), web domain manipulation (URL mistyping), and automated code execution conditions.
CompTIA threat taxonomy categorizes social engineering and malware based on their delivery mechanism and target.
2
Associate each term with its primary delivery mechanism.
Typosquatting targets URL typing errors; Dumpster Diving targets physical disposal areas; Logic Bomb relies on conditional software triggers; Smishing relies on cellular text messages.
Accurate alignment ensures proper selection of security controls for remediation.

Key Concept

Social Engineering Techniques and Threat Classifications
Estimated Time:2m 0s
Question 1177Question

An IT technician is troubleshooting a newly deployed guest Wi-Fi network in a medical clinic. Guests are able to connect to the WPA3-Personal wireless network using a shared passphrase, but several patients report that their mobile devices can discover and attempt to access local network resources, including shared medical printer queues and other connected guest devices. Which of the following configurations should the technician enable on the wireless access point to isolate guest traffic and limit their access strictly to the internet?

Show answer & explanation

Answer: Wireless Client Isolation (AP Isolation)

Answer

Enabling Wireless Client Isolation (AP Isolation) on the access point.
Wireless Client Isolation operates at the access point level to prevent connected wireless stations from communicating directly with one another or discovering local network resources on the same subnet. It ensures traffic from each client is routed strictly to the internet gateway.

Step-by-Step Solution

1
Identify the core problem described in the scenario
Connected guest devices are able to see and communicate with local network resources and other peer devices on the same wireless segment.
Standard SOHO or basic guest WLANs default to allowing peer-to-peer communication across the layer-2 network broadcast domain.
2
Evaluate wireless security mechanisms for peer segregation
Wireless Client Isolation restricts each connected endpoint so it can only talk to the default gateway (router), blocking intra-SSID client-to-client communication.
This guarantees guest devices remain isolated from internal network shares, printers, and neighboring endpoints.
3
Distinguish between authentication mechanisms and traffic management
Options like 802.1X/RADIUS or MAC filtering govern who can connect, but do not prevent connected devices on the same subnet from broadcasting to each other.
Authentication controls identity verification, whereas client isolation controls packet forwarding boundaries.

Key Concept

Wireless Client Isolation (AP Isolation)
Question 1178Question

A user logged into a Windows workstation attempts to install a signed device driver for a new peripheral. Before the installation script executes, the screen dims and a pop-up window appears requesting explicit confirmation to allow the app to make changes to the device. Which of the following Windows security features is responsible for generating this elevation prompt?

Show answer & explanation

Answer: User Account Control (UAC)

Answer

User Account Control (UAC)
User Account Control (UAC) is designed to improve Windows security by limiting application software to standard user privileges until an administrator explicitly authorizes an elevation request. When driver installations or administrative tasks occur, UAC notifies the user and asks for permission or credentials.

Step-by-Step Solution

1
Analyze the scenario requirements.
The operation involves installing a hardware driver, which requires system-level administrative privileges in Windows.
Installing drivers modifies system files and registry keys protected by the operating system.
2
Identify the operating system security boundary.
User Account Control (UAC) intercepts the administrative request and prompts the user on the Secure Desktop before granting elevated rights.
UAC prevents unauthorized background changes by requiring user consent or credentials.

Key Concept

User Account Control (UAC) Elevation Prompts
Estimated Time:45s
Question 1179Question

Match each macOS feature or Linux command-line tool to its primary administrative function.

Click a left item, then click its matching right item

Items

Time Machine
Spotlight
sudo
grep

Matches

Show answer & explanation

Answer

Time Machine pairs with automated native backup utility; Spotlight pairs with system-wide indexing search; sudo pairs with elevated administrative privilege execution; grep pairs with searching text patterns.
Each feature or tool is matched directly to its primary function: Time Machine handles automated backups in macOS; Spotlight provides desktop search and file indexing; sudo runs commands with root administrative rights; grep searches text for specified matching patterns.

Step-by-Step Solution

1
Identify the purpose of the native macOS features.
Time Machine is responsible for incremental disk backups, while Spotlight serves as the desktop search and system indexing tool.
These are primary GUI-based administrative features specific to macOS.
2
Identify the purpose of the CLI utilities shared across Unix-like systems.
The sudo command elevates permissions to root level, while grep searches files and terminal streams for matching text strings.
These standard CLI utilities are essential for macOS and Linux administration.

Key Concept

macOS native tools and standard Linux command-line utilities
Question 1180Question

A network administrator is hardening Windows 11 Enterprise desktop images for a public library computer lab. The organization's security policy mandates two strict requirements: standard user accounts must be blocked from initiating any privilege elevation requests (preventing credential prompt pop-ups), and local administrators performing maintenance must receive a consent prompt on an isolated screen before executing elevated tasks. Which TWO policy settings under Local Security Policy (`secpol.msc`) should the administrator configure to satisfy these security requirements?

Select all that apply

Show answer & explanation

Answer: User Account Control: Behavior of the elevation prompt for standard users — Automatically deny elevation requests; User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode — Prompt for consent on the secure desktop

Answer

The administrator should configure 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' and 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' to 'Prompt for consent on the secure desktop'.
Configuring 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' ensures that standard users cannot invoke elevation prompts or attempt credential entry. Configuring 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' to 'Prompt for consent on the secure desktop' forces administrators to confirm elevation on an isolated desktop, satisfying both security requirements.

Step-by-Step Solution

1
Identify the standard user security requirement
Standard users must not be able to elevate or view credential prompts.
Setting the policy 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' fulfills this by instantly blocking administrative elevation attempts from non-admin accounts.
2
Identify the administrative elevation security requirement
Administrators must confirm actions via a consent prompt on an isolated screen.
Setting 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' to 'Prompt for consent on the secure desktop' ensures administrators are prompted to allow execution on the secure desktop without needing to enter password credentials.

Key Concept

Windows Local Security Policy (secpol.msc) User Account Control Elevation Behaviors
PreviousPage 59 / 178Next
All practice questions — CompTIA A+ (Core 1 & Core 2) | Examkin