All practice questions

3551 questions

Question 1201Question

A field technician is tasked with resolving a corrupt print spooler service issue on a Windows workstation connected to a shared office multifunction printer. Place the following troubleshooting steps in the correct chronological order to clear the print queue and restore normal printing service.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct sequence to clear a stuck Windows print queue is: Stop the Print Spooler service, delete all files in %SystemRoot%\System32\spool\PRINTERS, restart the Print Spooler service, and print a test page to verify functionality.
The proper administrative procedure for resolving a locked or corrupt print queue requires stopping the Print Spooler service first to release OS file locks, deleting the cached spool files (.SHD and .SPL) located in %SystemRoot%\System32\spool\PRINTERS, restarting the service, and sending a test print job to confirm functional recovery.

Step-by-Step Solution

1
Stop the Print Spooler service.
Prevents active locks on spool files.
Windows holds active file handles on documents currently in the queue while the Print Spooler service is running.
2
Delete all files inside the PRINTERS spool folder (%SystemRoot%\System32\spool\PRINTERS).
Purges corrupted shadow (.SHD) and spool (.SPL) files.
Corrupted print jobs remain locked on disk until manually removed from the spooling directory.
3
Start the Print Spooler service.
Initializes a clean print subsystem.
The service must be running to receive and process new print tasks.
4
Send a test print request from the workstation.
Confirms problem resolution.
Verifying functionality ensures the print queue is accepting and transferring jobs to the printer successfully.

Key Concept

Windows Print Spooler Troubleshooting and Queue Remediation
Question 1202Question

A network technician is configuring a wireless network for a corporate office. Company policy mandates that each employee must authenticate using their own individual domain credentials via a centralized RADIUS server, rather than sharing a pre-shared passphrase. Which of the following wireless security standards should the technician implement?

Show answer & explanation

Answer: WPA3-Enterprise

Answer

WPA3-Enterprise
WPA3-Enterprise utilizes the 802.1X authentication framework, which forwards individual user credentials to a centralized RADIUS server for authentication against domain accounts.

Step-by-Step Solution

1
Identify the authentication requirement.
The requirement specifies authenticating users individually using domain credentials via RADIUS.
Enterprise security modes utilize 802.1X framework to interface with AAA servers like RADIUS.
2
Evaluate wireless security modes against the requirement.
WPA3-Enterprise provides 802.1X support for individual user logins, whereas Personal modes (PSK/SAE) rely on a single shared key.
Selecting an Enterprise mode satisfies the requirement for centralized, individual user access control.

Key Concept

Wireless Security Modes (Enterprise 802.1X vs. Personal PSK)
Question 1203Question

A systems administrator suspects that a Windows workstation on the corporate network is infected with a trojan after observing suspicious background network traffic. The administrator has already disconnected the workstation from the network to quarantine it and has disabled System Restore. According to the standard CompTIA malware remediation procedure, which of the following actions should the administrator take NEXT?

Show answer & explanation

Answer: Update the anti-malware software definitions and perform a complete system scan.

Answer

Update the anti-malware software definitions and perform a complete system scan.
The CompTIA 7-step malware remediation workflow follows a strict sequence: (1) Identify malware symptoms, (2) Quarantine infected systems, (3) Disable System Restore, (4) Remediate infected systems (update signatures and scan/remove), (5) Schedule updates and install OS patches, (6) Enable System Restore and create a restore point, and (7) Educate the end user. Since steps 1 through 3 are already completed, the next logical and required step is remediation via anti-malware updates and scanning.

Step-by-Step Solution

1
Analyze the current stage in the CompTIA 7-step malware removal process.
Steps 1 (Identify/Research), 2 (Quarantine), and 3 (Disable System Restore) have already been completed.
Following the rigid sequence prevents reinfection from restore points and contains the threat.
2
Determine the required 4th step in the process.
Step 4 is 'Remediate the infected systems'.
Remediation involves updating anti-malware signatures/definitions and scanning the machine to remove the active infection.

Key Concept

CompTIA 7-Step Malware Remediation Process
Estimated Time:45s
Question 1204Question

A systems administrator at a healthcare facility is investigating a security incident in the radiology department. Several workstations have lost access to local and network files, which now display a .locked file extension alongside a text file demanding cryptocurrency payment within 48 hours. During the initial investigation, the technician learns that an unidentified individual left several unlabeled USB flash drives labeled 'Q3 Executive Bonuses' in the staff lounge, which multiple employees plugged into their workstations. Which of the following threat types and attack vectors are demonstrated in this scenario? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Ransomware; Baiting

Answer

The threat types demonstrated in this scenario are Ransomware and Baiting.
Ransomware is demonstrated by the unauthorized encryption of user files coupled with a demand for cryptocurrency to restore access. Baiting is demonstrated by leaving malicious USB drives in a common work area with enticing labels to trick employees into introducing malware into the corporate environment.

Step-by-Step Solution

1
Analyze the malicious payload and symptoms described in the scenario.
The renaming of files with a .locked extension and the presence of a cryptocurrency extortion note confirms a file-encrypting malware attack.
Ransomware specifically targets data availability by encrypting files and demanding ransom for decryption.
2
Analyze the social engineering attack vector used to deliver the payload.
Leaving physical USB flash drives labeled enticingly ('Q3 Executive Bonuses') in a common employee area exploits curiosity to compromise systems.
Baiting uses physical media pre-loaded with malware placed strategically to trick users into connecting them to internal network devices.

Key Concept

Social Engineering Vectors (Baiting) and Malware Classifications (Ransomware)
Estimated Time:2m 0s
Question 1205Question

A desktop support technician is performing an on-site visit to troubleshoot a printing issue at a user's workstation. During the repair, the user receives an urgent business phone call. Which of the following is the most appropriate action for the technician to take?

Show answer & explanation

Answer: Politely excuse themselves or pause quietly to avoid distracting the user while they complete the call.

Answer

Politely excuse themselves or pause quietly to avoid distracting the user while they complete the call.
The option advocating to politely excuse oneself or pause quietly is correct because it respects the customer's privacy and active business responsibilities, strictly adhering to professional IT communication standards.

Step-by-Step Solution

1
Evaluate the customer environment and situation.
Identify that the user is engaged in an important business phone call during an active desk-side visit.
Technicians must adapt to the customer's environment and minimize workplace disruption.
2
Select the response that aligns with professional interpersonal communication guidelines.
Choose to pause quietly or temporarily step away until the call ends.
CompTIA professional standards require technicians to respect user privacy, avoid interruptions, and maintain professional etiquette.

Key Concept

Demonstrating proper communication etiquette and respecting customer privacy during on-site support visits.
Estimated Time:45s
Question 1206Question

An IT technician is performing a clean installation of Windows 11 Pro on a new desktop workstation equipped with a dedicated RAID storage controller. When reaching the partition setup screen during installation, no target storage drives are displayed. Which of the following actions should the technician take to resolve this issue and continue the installation? (Select TWO).

Select all that apply

Show answer & explanation

Answer: Place the storage controller device drivers on a USB flash drive and click Load Driver on the installation screen.; Access the system UEFI/BIOS setup to verify that the storage controller is detected and properly configured.

Answer

The technician should load the storage controller driver from a USB flash drive using the 'Load Driver' option on the partition selection screen, and verify in UEFI/BIOS setup that the storage controller is detected and enabled.
When Windows Setup cannot discover connected drives on a new build with a dedicated RAID controller, it indicates the installer media lacks the required storage controller driver. Supplying the manufacturer's driver via the 'Load Driver' interface makes the storage array visible. Additionally, checking UEFI/BIOS ensures the controller hardware is powered, enabled, and initialized properly.

Step-by-Step Solution

1
Check system firmware configuration
Confirm that the RAID storage controller is detected by UEFI/BIOS and that the controller mode is correctly configured.
Hardware must be initialized and recognized by firmware before any operating system installer can detect attached drives.
2
Obtain and supply hardware drivers during OS setup
Load third-party mass storage drivers from an external USB drive by selecting 'Load Driver' on the disk selection screen.
Standard Windows installation media may lack proprietary RAID drivers required to communicate with specific disk controller hardware.

Key Concept

Mass Storage Controller Driver Loading during OS Clean Installation
Question 1207Question

A desktop support technician is configuring static IPv4 settings on a Windows 11 Pro workstation in a corporate network. The workstation can successfully communicate with local IP addresses and access external internet sites via FQDN. However, users are unable to access internal network shares using short single-label hostnames (such as `\\fileserver`), while using the fully qualified domain name (such as `\\fileserver.contoso.com`) works properly. Which of the following TCP/IP settings should the technician configure in Windows to resolve short hostname resolution?

Show answer & explanation

Answer: Append the primary DNS suffix under Advanced TCP/IP DNS settings.

Answer

Configure the Primary DNS suffix under Advanced TCP/IP DNS settings.
Appending the primary domain DNS suffix under Advanced TCP/IP DNS properties instructs the Windows DNS client to automatically append the specified domain suffix whenever an un-dotted, single-label hostname is queried, converting `fileserver` to `fileserver.contoso.com` behind the scenes.

Step-by-Step Solution

1
Analyze the reported symptom
Full FQDN resolution works (`fileserver.contoso.com`), but single-label resolution (`fileserver`) fails.
When a user inputs a single-label hostname, the OS DNS client needs a DNS suffix search list to append the domain name to form a complete FQDN query.
2
Identify the required network configuration setting
Locate Advanced TCP/IP Settings -> DNS tab in the IPv4 properties of the Network Adapter.
Configuring 'Append primary and connection specific DNS suffixes' or specifying explicit suffixes enables automatic FQDN resolution for short names.

Key Concept

Windows TCP/IP Advanced DNS Suffix Search Order and Single-Label Hostname Resolution
Estimated Time:1m 0s
Question 1208Question

A helpdesk technician needs to perform remote administration on a branch office computer. The remote computer is joined to the network via an active SSL-VPN connection, and network firewall logs confirm that traffic on TCP port 3389 is successfully passing through to the target host. However, when the technician attempts to initiate a Remote Desktop (RDP) connection, the session request is refused by the remote host. Upon verifying system details, the technician notes that the target system is running Windows 11 Home Edition. Which of the following is the PRIMARY cause of the connection failure?

Show answer & explanation

Answer: Windows 11 Home Edition cannot act as an RDP host to accept incoming Remote Desktop connections.

Answer

Windows 11 Home Edition cannot act as an RDP host to accept incoming Remote Desktop connections.
Microsoft Windows 11 Home Edition allows users to initiate outgoing Remote Desktop sessions as a client, but it lacks the built-in host capability required to receive incoming RDP connections. To host an RDP session natively, the target system must be upgraded to Windows 11 Pro, Enterprise, or Education.

Step-by-Step Solution

1
Analyze the network configuration and firewall state provided in the scenario.
Network connectivity over the VPN is established and traffic on TCP port 3389 (default RDP port) is allowed through the network firewall.
This rules out network-level firewall blockage or routing issues.
2
Evaluate the target operating system edition and its supported remote access feature set.
The target computer is running Windows 11 Home Edition.
Microsoft restricts the RDP host feature to Windows Pro, Enterprise, and Education editions.
3
Determine the cause of the connection failure.
The RDP server host component is unavailable on the target device due to OS edition limits.
While Windows Home edition devices can initiate outbound RDP client connections to other machines, they cannot accept inbound RDP host connections.

Key Concept

Remote Desktop Protocol (RDP) Host Support Limitations Across Windows OS Editions
Estimated Time:2m 0s
Question 1209Question

A system administrator needs to render confidential data completely unrecoverable on several decommissioned magnetic hard disk drives (HDDs) without physically destroying the drives. Which of the following data sanitization methods should the administrator use?

Show answer & explanation

Answer: Degaussing

Answer

Degaussing is the correct sanitization method for magnetic media when physical destruction is not used.
Degaussing uses a strong magnetic field to disrupt magnetic domains on magnetic drives and tapes, rendering data entirely unrecoverable while leaving the chassis intact.

Step-by-Step Solution

1
Identify the media type and destruction requirements.
The target drives are magnetic HDDs that need full data sanitization without physical destruction.
Different storage media technologies require distinct destruction or sanitization methods.
2
Evaluate data sanitization techniques suited for magnetic storage.
Degaussing disrupts magnetic domains, completely eradicating data stored on magnetic tape and disk platters.
Degaussing permanently neutralizes magnetic alignment without physical shredding or crushing.

Key Concept

Data Destruction and Disposal Methods
Question 1210Question

A desktop technician is troubleshooting a legacy 32-bit line-of-business application on a Windows 11 Pro workstation. When a standard user runs the application, configuration changes are saved without issue. However, when an administrative user logs in and opens the application normally (without selecting 'Run as administrator'), the application fails to save changes and throws a permission denied error. An inspection reveals that the application attempts to write settings to C:\Program Files (x86)\LegacyApp\config.ini, where NTFS permissions grant Write access exclusively to the local Administrators group. Which of the following best explains why the application saves configuration changes for the standard user but fails for the administrator?

Show answer & explanation

Answer: User Account Control file virtualization redirects writes to a user-specific VirtualStore directory for standard user tokens, but UAC virtualization is disabled for accounts belonging to the Administrators group.

Answer

User Account Control (UAC) file virtualization intercepts and redirects write attempts to protected system locations like Program Files for standard users into %LOCALAPPDATA%\VirtualStore. However, for administrative accounts operating under Admin Approval Mode, UAC file and registry virtualization is disabled, so direct write attempts to protected directories fail when the application is launched without full administrative privilege elevation.
User Account Control (UAC) includes a legacy compatibility mechanism called file and registry virtualization. When a 32-bit legacy application run by a standard user attempts to write to protected system directories like C:\Program Files (x86), Windows transparently redirects the write operation to %LOCALAPPDATA%\VirtualStore. However, for security and data integrity reasons, UAC virtualization is explicitly disabled for members of the local Administrators group. When an administrator launches the application without elevating ('Run as administrator'), the process runs with a filtered standard user token, but because virtualization is disabled for admin accounts, the direct write attempt to the protected folder is blocked by NTFS permissions.

Step-by-Step Solution

1
Analyze how User Account Control (UAC) handles legacy 32-bit applications writing to protected system directories.
Identify that 32-bit legacy applications writing to C:\Program Files (x86) trigger UAC virtualization for standard users, seamlessly redirecting writes to %LOCALAPPDATA%\VirtualStore.
UAC includes virtualization technology to prevent legacy applications from failing when attempting to write to system-protected file and registry locations.
2
Evaluate the behavior of UAC Admin Approval Mode for accounts in the local Administrators group.
Recognize that UAC disables file and registry virtualization for administrative accounts to prevent split-token inconsistencies.
Administrators are expected to run software with proper elevated privileges rather than relying on VirtualStore redirection.
3
Compare the execution state of the standard user token versus the unelevated administrator token.
The standard user succeeds due to VirtualStore redirection, while the unelevated administrator fails because virtualization is inactive and the token lacks elevated NTFS write rights.
Without explicit privilege elevation ('Run as administrator'), the administrator's filtered token cannot write directly to C:\Program Files (x86), causing the operation to fail.

Key Concept

UAC File and Registry Virtualization Behavior
Question 1211Question

A security technician needs to configure a standalone Windows 11 Pro workstation so that standard user accounts are automatically denied elevation requests without displaying a UAC prompt. Place the administrative configuration steps in the correct chronological order from first to last.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct order of administrative steps is: 1) Open the Run dialog box, type secpol.msc, and press Enter -> 2) Expand Security Settings > Local Policies and select Security Options -> 3) Double-click User Account Control: Behavior of the elevation prompt for standard users -> 4) Set the local security setting dropdown to Automatically deny elevation requests and click OK.
To enforce auto-denial of elevation requests for standard users on Windows Pro or Enterprise editions, an administrator must launch the Local Security Policy console (secpol.msc), navigate to Security Settings > Local Policies > Security Options, locate 'User Account Control: Behavior of the elevation prompt for standard users', and change its value to 'Automatically deny elevation requests'.

Step-by-Step Solution

1
Launch the Local Security Policy management console using the command secpol.msc.
The Local Security Policy window opens.
Fine-grained UAC behavior rules for distinct account types cannot be set in Control Panel and require the secpol.msc console.
2
Navigate through the policy tree under Security Settings to Local Policies, then select Security Options.
The right pane displays all configurable security option policies.
All administrative User Account Control policies reside within the Security Options folder.
3
Locate and open 'User Account Control: Behavior of the elevation prompt for standard users'.
The policy properties dialog appears.
This specific policy determines whether standard users receive a credential prompt or are blocked directly.
4
Change the security setting to 'Automatically deny elevation requests' and save changes.
Standard users will no longer see UAC prompts when trying to run administrative tasks; requests fail immediately.
Selecting this option fulfills the security requirement to enforce automatic denial without prompt interaction.

Key Concept

Configuring UAC elevation prompt behavior for standard accounts using Local Security Policy (secpol.msc)
Estimated Time:1m 30s
Question 1212Question

A network security administrator is deploying a wireless network for an enterprise client's corporate headquarters. The client's security policy strictly requires individual user authentication backed by a centralized RADIUS server, along with modern encryption that eliminates legacy cipher vulnerabilities. Which of the following wireless security configurations should the administrator implement to meet these requirements?

Show answer & explanation

Answer: WPA3-Enterprise utilizing 802.1X authentication with AES encryption

Answer

WPA3-Enterprise utilizing 802.1X authentication with AES encryption
WPA3-Enterprise provides 802.1X framework integration with centralized RADIUS servers for individual credential authentication, while utilizing modern AES-based cipher suites (such as GCMP/CCMP) to secure wireless communications.

Step-by-Step Solution

1
Identify the authentication requirement
Individual user authentication backed by a RADIUS server requires an Enterprise security mode using 802.1X rather than a Personal (Pre-Shared Key / SAE) mode.
Enterprise modes integrate with centralized identity providers (such as RADIUS and Active Directory) to authenticate each user individually.
2
Evaluate the encryption and protocol security requirements
WPA3-Enterprise provides state-of-the-art encryption algorithms (CCMP/GCMP) and eliminates legacy, insecure ciphers such as TKIP.
Legacy ciphers like TKIP are deprecated due to security vulnerabilities, and Personal modes cannot provide per-user authentication logs or individual credential revocation.
3
Select the correct wireless configuration
WPA3-Enterprise with 802.1X authentication meets both the centralized per-user authentication requirement and modern encryption standards.
It combines RADIUS-backed 802.1X EAP authentication with robust modern ciphers.

Key Concept

WPA2/WPA3 Enterprise vs. Personal Authentication and Encryption Standards
Question 1213Question

An IT security analyst is investigating a breach where multiple compliance officers' workstations were infected with spyware simultaneously. Email security logs show no suspicious incoming messages, external USB storage devices are blocked via Group Policy, and physical access logs show no unauthorized entry. Analysis reveals that all affected personnel regularly visit a specific third-party industry news website, which had been secretly compromised to serve malicious scripts to site visitors. Which of the following attack types best describes this scenario?

Show answer & explanation

Answer: Watering hole attack

Answer

Watering hole attack
A watering hole attack occurs when an attacker compromises a specific website frequently visited by a target organization or department, planting malware to infect users upon visit. In this scenario, since email logs showed no malicious emails and USB ports were disabled, the infection of multiple users via a frequented third-party news site precisely fits the definition of a watering hole attack.

Step-by-Step Solution

1
Analyze the attack vectors ruled out by the scenario constraints.
Email security logs rule out spear phishing; Group Policy rules out USB baiting; physical access logs rule out physical tampering.
Elimination of vector possibilities based on provided security logs and administrative controls.
2
Identify the common vulnerability exploitation method among all affected users.
All affected workstations visited a compromised third-party industry website frequented by the target department.
Determining the common origin of the malicious payload delivery.
3
Correlate the attack delivery method with CompTIA threat classifications.
Compromising a specific website known to be used by a targeted group to infect their systems is defined as a watering hole attack.
Matching threat behavior to standard security terminology.

Key Concept

Watering Hole Attack Identification
Question 1214Question

A support technician responds to an escalated helpdesk ticket where a remote user cannot access shared network drives following a recent department VLAN migration. The technician runs `ipconfig /all` and `nslookup` on the client machine, determining that the workstation is receiving an Automatic Private IP Addressing (APIPA) address because the DHCP relay agent on the new VLAN router interface was omitted. Reconfiguring the router requires specialized privileges held only by the Network Infrastructure Team. Which of the following is the most appropriate action for the technician to take NEXT within the ticketing system workflow?

Show answer & explanation

Answer: Record all diagnostic steps, command output, and root-cause analysis in the ticket work log, escalate the ticket to the Network Infrastructure Team queue, and update the ticket status accordingly.

Answer

The technician should thoroughly record all diagnostic results and command outputs in the ticket work log, update the status, and escalate the ticket to the Network Infrastructure Team queue.
The correct action is to document all completed diagnostic commands, specific error findings, and isolated root causes in the ticketing system's internal work log before reassigning the ticket to the appropriate escalation queue (Network Infrastructure). In IT service management and CompTIA operational standards, thorough documentation at the point of handoff ensures seamless escalation, preserves historical data, and prevents secondary technicians from repeating work.

Step-by-Step Solution

1
Analyze the technical scenario and isolation results.
The technician confirmed through command outputs (`ipconfig /all`) that the host has an APIPA address due to a missing DHCP relay on the router.
Establishing root cause determines which specialized team owns the remediation step.
2
Identify the required ticketing system escalation workflow step.
Standard operational procedures mandate documenting all troubleshooting steps taken and empirical data collected into the internal ticket work log prior to reassignment.
Complete documentation maintains audit trails, prevents redundant diagnostic work by escalation teams, and adheres to IT service management best practices.
3
Reassign and update ticket state.
Escalate to the Network Infrastructure queue while updating the ticket lifecycle status to reflect active escalation.
Ensures ownership is formally transferred without closing the ticket or placing inappropriate responsibility back onto the user.

Key Concept

Incident Lifecycle Management & Escalation Documentation Workflows
Question 1215Question

A corporate user reports that a custom line-of-business logistics application on an Android smartphone consistently freezes and crashes whenever attempting to open a large local database view. Other applications on the device run normally, and device storage is 45% free. A technician has already verified that the app is updated to the latest build, performed a soft reset of the mobile device, and force-stopped the app, but the issue persists. Following standardCompTIA least-invasive troubleshooting methodology, which of the following actions should the technician perform NEXT?

Show answer & explanation

Answer: Clear the application's cache directory in the mobile operating system settings.

Answer

Clear the application's cache directory in the mobile operating system settings.
Clearing the application cache is the correct next step according to CompTIA least-invasive troubleshooting procedures. After force-stopping the app and restarting the device, clearing temporary cached files addresses potential file corruption specific to that application without deleting user data or application configuration settings.

Step-by-Step Solution

1
Evaluate the current troubleshooting status
The technician has already performed initial steps: verified updates, force-stopped the app, and soft-reset the device.
Troubleshooting mobile OS performance requires following a structured sequence from least invasive to most invasive.
2
Determine the next least-invasive action for application-specific crash remediation
Clearing the application cache isolates temporary file corruption without wiping stored user accounts or local settings.
App cache contains non-essential temporary data; removing it often resolves freeze/crash loops without causing data loss.
3
Compare against more invasive options
Clearing app data or performing a factory reset are more disruptive and should only be attempted if clearing the cache fails.
Maintaining least-invasive methodology preserves user configurations and minimizes device downtime.

Key Concept

Mobile OS Application Troubleshooting Order of Volatility and Invasiveness
Question 1216Question

Match each Windows administrative scenario with the most appropriate management utility or snap-in used to accomplish the task.

Click a left item, then click its matching right item

Items

Configuring account lockout policies, group memberships, and password expiration settings for local accounts on a standalone workstation.
Reviewing system stability trends, application crashes, and Windows update history over a chronological timeline.
Creating a system Data Source Name (DSN) to connect a database application to a local SQL engine.
Configuring an automated script to execute automatically whenever a specific system Event ID occurs.

Matches

Show answer & explanation

Answer

Local account administration maps to Local Users and Groups (lusrmgr.msc); reviewing historical stability trends maps to Reliability Monitor; database connection DSN configuration maps to ODBC Data Sources (odbcad32.exe); and event-triggered task automation maps to Task Scheduler (taskschd.msc).
Each scenario maps precisely to its dedicated administrative tool: Local Users and Groups controls local user security properties, Reliability Monitor charts historical stability trends, ODBC Data Sources configures application database connection strings, and Task Scheduler automates tasks based on time or event conditions.

Step-by-Step Solution

1
Identify the primary administrative objective for each listed scenario.
Categorize tasks into user account management, stability analysis, database connection provisioning, and task automation.
Windows separates management functionality across dedicated consoles and tools.
2
Match user management tasks to local security utilities.
Configuring local accounts and group membership maps directly to Local Users and Groups snap-in.
Local Users and Groups controls local user properties and rights on non-domain Windows Professional/Enterprise installations.
3
Match diagnostic and troubleshooting scenarios to appropriate performance/stability utilities.
Timeline-based stability and crash history reviews map to Reliability Monitor.
Reliability Monitor consolidates event logs into a daily stability index and graphical trend chart.
4
Match database and automation requirements to specialized utilities.
DSN configuration maps to ODBC Data Sources, while Event ID-triggered execution maps to Task Scheduler.
ODBC manages database connection drivers, while Task Scheduler automates operations based on event triggers.

Key Concept

Windows Administrative Consoles and System Management Utilities
Question 1217Question

Match each macOS system feature or Linux/macOS command-line tool to its primary administrative function.

Click a left item, then click its matching right item

Items

df -h
sudo chown -R
FileVault
SMC reset

Matches

Show answer & explanation

Answer

'df -h' matches displaying file system disk space in human-readable units; 'sudo chown -R' matches recursively changing file/directory ownership under superuser rights; 'FileVault' matches enabling full-disk encryption on macOS volumes; 'SMC reset' matches resolving low-level hardware power and thermal fan issues.
Each tool matches its definitive system administration role: 'df -h' displays storage volume usage in human-readable format; 'sudo chown -R' recursively modifies file ownership across directory trees under superuser permissions; 'FileVault' provides native macOS full-disk encryption; and an SMC reset restores low-level power and thermal management functions.

Step-by-Step Solution

1
Analyze storage monitoring CLI tools
Map 'df -h' to the display of mounted file system disk utilization formatted in human-readable sizes (GB/MB).
The 'df' (disk free) utility checks overall volume utilization, and the '-h' flag converts raw block counts to human-readable units.
2
Analyze file system administrative CLI utilities
Map 'sudo chown -R' to recursively modifying file and directory ownership.
The 'chown' utility alters user/group ownership, the '-R' option traverses directories recursively, and 'sudo' ensures execution with elevated administrative rights.
3
Analyze macOS native security tools
Map 'FileVault' to full-disk volume encryption.
FileVault is the native macOS feature that encrypts the system disk to protect stored data from unauthorized access.
4
Analyze macOS hardware troubleshooting utilities
Map 'SMC reset' to restoring low-level power and thermal management features.
The System Management Controller (SMC) manages physical subsystem controls including thermal cooling fans, power button responsiveness, and battery charging logic.

Key Concept

macOS features and Linux command-line tools for storage management, security, file administration, and hardware troubleshooting.
Question 1218Question

A network administrator sets up a secure IPsec VPN tunnel and opens TCP port 3389 on the corporate firewall to allow remote management of a newly deployed off-site workstation. A tier 2 support technician attempts to establish an unattended Remote Desktop Protocol (RDP) session to the workstation's IP address over the VPN. The connection fails to initiate, even though network diagnostic tests confirm active IP connectivity and name resolution. Upon reviewing the system specifications, the technician notes that the remote computer was imaged with Windows 11 Home edition. Which of the following best explains why the Remote Desktop connection failed, and what is the required solution to enable native unattended RDP administration?

Show answer & explanation

Answer: Windows 11 Home edition does not support acting as an RDP server to host incoming remote desktop sessions; the operating system must be upgraded to Windows 11 Pro or Enterprise edition.

Answer

Windows 11 Home edition does not support acting as an RDP host to accept incoming Remote Desktop sessions. The operating system must be upgraded to Windows 11 Pro or Enterprise to enable native incoming RDP over TCP port 3389.
The correct option identifies that Windows Home editions (including Windows 10 and Windows 11 Home) lack the built-in host server functionality required to accept incoming Remote Desktop Protocol (RDP) sessions. While a Windows Home system can run the RDP client software to connect to other computers, it cannot be remotely managed via native RDP unless the operating system is upgraded to Windows Pro, Enterprise, or Education edition.

Step-by-Step Solution

1
Analyze OS capabilities regarding remote access protocols.
Identified that Windows 11 Home edition supports outgoing RDP client connections but restricts incoming RDP server hosting capabilities.
Microsoft reserves the incoming RDP server service for Windows Pro, Enterprise, and Education editions.
2
Evaluate alternative built-in Windows tools against the scenario requirements.
Determined that Microsoft Remote Assistance (MSRA) requires an interactive local user to accept an invitation, making it unsuitable for unattended server or workstation maintenance.
Unattended access requires an active background remote desktop host service without requiring a local user present to acknowledge prompts.
3
Select the correct administrative remediation step.
Upgrading the OS edition from Windows 11 Home to Windows 11 Pro or Enterprise enables the Remote Desktop host feature on standard TCP port 3389.
Upgrading the operating system edition unlocks advanced corporate administrative features, including incoming RDP hosting and domain integration.

Key Concept

Remote Access Technologies and OS Edition Feature Restrictions
Estimated Time:3m 0s
Question 1219Question

A helpdesk technician is assisting a user on a Windows 11 Home workstation who attempts to open the Local Security Policy console (secpol.msc) to configure password policy settings. When running the command, Windows displays an error stating that the file cannot be found. Which of the following explains why this management console is unavailable?

Show answer & explanation

Answer: The Local Security Policy snap-in is not included in the Home edition of Windows.

Answer

The Local Security Policy snap-in is not included in the Home edition of Windows.
Microsoft Windows Home editions do not include advanced administrative policy snap-ins such as Local Security Policy (secpol.msc) or Local Group Policy Editor (gpedit.msc). Attempting to launch these MMC snap-ins on a Home edition results in a file not found error because the files are omitted from the installation image.

Step-by-Step Solution

1
Identify the OS edition and requested utility in the scenario.
The workstation is running Windows 11 Home, and the user is attempting to launch Local Security Policy (secpol.msc).
Feature availability in Windows varies across editions.
2
Evaluate feature support for Windows Home versus Pro/Enterprise editions.
Advanced security tools such as secpol.msc, gpedit.msc, and BitLocker are feature-restricted and only available on Windows Pro, Enterprise, and Education editions.
Microsoft excludes domain management and local group policy snap-ins from Home editions by design.
3
Select the option that correctly identifies the Windows edition restriction.
The option explaining that Local Security Policy is not included in the Home edition is correct.
This directly explains why secpol.msc is missing from the operating system.

Key Concept

Windows Edition Security Feature Constraints
Estimated Time:45s
Question 1220Question

An IT security technician is designing physical entry security for a high-security server room hosting sensitive financial records. Organization policy mandates implementing measures that actively prevent tailgating (piggybacking) at the doorway, as well as enforcing multi-factor physical authentication that combines a physical security token with a biometric characteristic. Which of the following physical security controls should the technician implement to satisfy these requirements? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Access control vestibule with interlocking doors; Smart card reader paired with a biometric fingerprint scanner

Answer

The correct controls are an access control vestibule with interlocking doors and a smart card reader paired with a biometric fingerprint scanner.
An access control vestibule (mantrap) provides a physical enclosure with interlocking doors that ensures only one person can pass through authentication at a time, directly preventing tailgating. Pairing a smart card reader with a biometric fingerprint scanner enforces multi-factor physical authentication by requiring both a physical possession factor (smart card) and an inherent biological factor (fingerprint).

Step-by-Step Solution

1
Identify the physical security requirement for preventing tailgating at the server room entrance.
Select an access control vestibule (mantrap), which uses a dual-door interlocking mechanism to restrict entry to one person at a time.
Mantraps explicitly block piggybacking/tailgating by preventing the inner door from opening while the outer door is open.
2
Identify the requirement for multi-factor physical authentication.
Select the combination of a smart card badge reader and a biometric fingerprint scanner.
Multi-factor authentication requires combining two distinct authentication factors: something you have (smart card) and something you are (fingerprint biometric).

Key Concept

Physical Access Control and Multi-Factor Physical Authentication
PreviousPage 61 / 178Next
All practice questions — CompTIA A+ (Core 1 & Core 2) | Examkin