All practice questions

3551 questions

Question 1761Question

Match each remote access technology or protocol on the left with its defining operational characteristic and port specification on the right.

Click a left item, then click its matching right item

Items

Secure Shell (SSH)
Remote Desktop Protocol (RDP)
Microsoft Remote Assistance (MSRA)
Telnet

Matches

Show answer & explanation

Answer

Secure Shell (SSH) pairs with encrypted CLI over TCP port 22. Remote Desktop Protocol (RDP) pairs with full graphical control over TCP port 3389 that locks local sessions. Microsoft Remote Assistance (MSRA) pairs with invitation-based interactive session control. Telnet pairs with unencrypted cleartext CLI over TCP port 23.
Each technology is mapped according to standard network port assignments and session management behaviors. Secure Shell (SSH) encrypts terminal sessions on TCP port 22; Remote Desktop Protocol (RDP) provides exclusive GUI management on TCP port 3389; Microsoft Remote Assistance (MSRA) uses invitations for collaborative remote assistance; and Telnet sends unencrypted terminal data over TCP port 23.

Step-by-Step Solution

1
Analyze command-line remote access tools based on security and port numbers.
SSH provides encrypted administration using TCP port 22, whereas Telnet sends unencrypted cleartext data over TCP port 23.
Distinguishing secure protocols from insecure legacy protocols is critical for operational procedures.
2
Analyze Windows graphical remote access tools based on session handling and user interaction.
RDP uses TCP port 3389 and creates an exclusive session that locks the local monitor, whereas MSRA uses user-initiated invitations to allow dual-view interactive troubleshooting.
RDP is designed for remote workspace access, while MSRA is designed for real-time user support.
3
Map each protocol or tool to its exact operational definition.
All four items are matched to their corresponding characteristics.
Ensures complete alignment with CompTIA remote access specifications.

Key Concept

Remote Access Protocols, Default Ports, and Operational Behaviors
Question 1762Question

A field technician reports that their enterprise-managed mobile smartphone is repeatedly displaying untrusted security certificate warnings when accessing internal company portals. Network logs indicate that sensitive traffic is being intercepted via a custom root certificate authority (CA) installed alongside an unapproved third-party configuration profile. Which of the following actions should the technician take FIRST to eliminate the unauthorized traffic interception?

Show answer & explanation

Answer: Remove the unauthorized configuration profile and delete its associated root certificate from the device settings.

Answer

Removing the unauthorized configuration profile and deleting the associated root certificate from the device settings is the most effective immediate action.
Removing the unauthorized configuration profile and deleting the untrusted root certificate directly neutralizes the Man-in-the-Middle (MitM) threat by removing the malicious trust anchor responsible for SSL/TLS interception warnings.

Step-by-Step Solution

1
Identify the cause of the untrusted certificate warning and traffic interception.
Discovered that a third-party configuration profile injected an unapproved custom root certificate onto the device.
Root CA certificates explicitly allow an entity to issue and validate trusted SSL/TLS certificates for traffic interception (Man-in-the-Middle).
2
Select the immediate remediation step to restore device trust integrity.
Access the mobile OS security settings to delete the malicious configuration profile and revoke the untrusted CA certificate.
Directly removing the malicious trust anchor stops unauthorized decrypt-and-forward proxying of HTTPS sessions.

Key Concept

Mobile Device Configuration Profile & Root Certificate Remediation
Estimated Time:2m 0s
Question 1763Question

A storage area network (SAN) engineer is preparing a change request to update the microcode on an enterprise SAN array hosting critical Virtual Desktop Infrastructure (VDI) datastores. The engineer has defined the purpose and scope of the change, completed a risk analysis regarding potential storage disruption, created a step-by-step implementation plan, and established post-implementation testing protocols. Prior to presenting this request to the Change Advisory Board (CAB) for formal authorization, which of the following mandatory change management components must the engineer add to complete the change documentation?

Show answer & explanation

Answer: A detailed rollback plan outlining specific procedures to revert the storage array microcode and configuration to its prior operational state if the update fails.

Answer

A detailed rollback plan outlining specific procedures to revert the storage array microcode and configuration to its prior operational state if the update fails.
The correct answer emphasizes the necessity of a documented rollback plan. Standard CompTIA change management workflows mandate that every proposed change include a clear purpose, scope, risk assessment, implementation plan, rollback plan, end-user notification, CAB authorization, and post-implementation testing. Without a predefined strategy to revert changes, the risk of unrecoverable downtime is unacceptably high.

Step-by-Step Solution

1
Analyze the change request preparation phase described in the scenario.
Identified existing components: purpose, scope, risk analysis, implementation plan, post-implementation testing, and end-user notification strategy.
CompTIA change management process mandates specific documentation requirements prior to CAB submission.
2
Evaluate missing prerequisite components for CAB submission.
Recognized that a documented rollback (backout) plan has not yet been defined.
Without a rollback plan, the organization cannot mitigate risk if the microcode update causes unforeseen system failure or data corruption.
3
Select the correct mandatory documentation step.
Determined that developing a rollback plan is the required next step before formal CAB authorization.
CAB approval requires verification that services can be safely restored to a baseline state if unexpected issues occur.

Key Concept

Core Elements of Formal Change Documentation
Question 1764Question

A help desk technician has just finished resolving a network printer configuration issue on a user's workstation. According to standard ticketing system workflows, which of the following elements must be recorded in the ticket's final resolution log? (Select TWO).

Select all that apply

Show answer & explanation

Answer: A detailed description of the troubleshooting steps performed and the specific solution applied; Confirmation that the user verified proper functionality and agreed the problem is resolved

Answer

Proper resolution documentation requires a detailed record of the troubleshooting steps and solution applied, as well as explicit confirmation of user verification.
Complete resolution logging requires detailing the technical resolution steps and confirming with the end-user that functionality is restored. These entries establish reliable knowledge base records and ensure service quality.

Step-by-Step Solution

1
Identify the mandatory components of a complete ticket resolution record.
Comprehensive documentation requires technical details of the resolution and proof of user verification.
Standard ticketing workflows mandate clear technical records for future reference and customer satisfaction confirmation before closing tickets.
2
Evaluate technical documentation requirements.
Documenting specific troubleshooting steps and the applied fix provides accurate historical data for the IT knowledge base.
Omitting technical steps makes it impossible for other technicians to learn from past incidents.
3
Evaluate user interaction and closure requirements.
Obtaining user verification confirms that the system operates as expected in the user's working environment.
Tickets should not be closed unilaterally without verifying that the issue is completely resolved from the end-user's perspective.

Key Concept

Incident Resolution Documentation and Verification Workflows
Estimated Time:1m 0s
Question 1765Question

A tier 2 remote support technician connects to a end-user's system to resolve a recurring application freeze that is impacting the user's daily deadline. The user expresses frustration about the downtime and asks what is taking so long. Which of the following professional communication and user interaction practices should the technician demonstrate in this situation? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Ask for explicit permission before taking control of the remote screen or interacting with the user's workspace.; Practice active listening by allowing the user to explain their frustration and issue details without interrupting.

Answer

The technician should practice active listening without interrupting the user and obtain explicit permission before taking control of the remote desktop workspace.
The correct responses involve practicing active listening by allowing the user to describe their situation uninterrupted, as well as securing explicit permission before interacting with or controlling the customer's remote workstation environment. These actions uphold professionalism, de-escalate tension, and protect user privacy.

Step-by-Step Solution

1
Evaluate de-escalation and listening techniques for customer interaction.
Identified that allowing the customer to express their concerns completely without interruption demonstrates active listening and maintains a professional tone.
De-escalating an anxious or frustrated user requires patience and active listening prior to diagnostic troubleshooting.
2
Apply customer property and privacy protocols during remote support.
Identified that requesting permission before initiating screen control or navigating user files respects user privacy and property.
Technicians must never take control or alter a customer's environment without prior consent.

Key Concept

Professional customer communication, active listening, and respect for customer property and privacy during remote IT support sessions.
Question 1766Question

A tier 1 service desk technician has finished resolving a workstation software issue caused by a corrupted application configuration file. According to standard ticketing workflow and documentation best practices, which of the following elements MUST be documented in the ticket resolution entry before it can be closed? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: The identified root cause and the specific resolution steps performed to fix the issue; Formal confirmation from the end user verifying that the application is functioning as expected

Answer

The resolution entry must include the identified root cause along with specific steps performed, as well as formal confirmation from the end user verifying functionality.
Complete ticket closure documentation requires both technical fidelity (documenting the root cause and detailed resolution steps taken) and procedural verification (obtaining confirmation from the end user that the issue is resolved).

Step-by-Step Solution

1
Identify mandatory ticket closure components under standard IT support guidelines.
Tickets require clear documentation of what caused the issue, what was done to fix it, and verification of user satisfaction.
Clear work notes allow knowledge base creation and prevent premature closing of unresolved issues.
2
Evaluate technical documentation details.
Recording the root cause and exact technical resolution steps ensures auditability and aids other technicians facing similar issues.
Complete resolution notes reduce mean time to resolution (MTTR) across the team.
3
Evaluate operational workflow verification steps.
User confirmation confirms that testing succeeded in the production environment from the user's perspective.
Closing a ticket without user verification leads to reopened tickets and poor service quality.

Key Concept

Incident Ticket Closure Documentation and Verification Workflow
Question 1767Question

A cybersecurity analyst is preparing to transfer a compromised server hard drive to an external forensic laboratory for legal analysis. The internal incident log currently includes the drive's model and serial number, the date and time of initial seizure, the acquiring technician's signature, and the secure storage room location. Which of the following details MUST be recorded on the chain-of-custody form at the moment of handoff to maintain evidence admissibility?

Show answer & explanation

Answer: The recipient's name, signature, and the exact date and time of the physical transfer

Answer

The recipient's name, signature, and the exact date and time of the physical transfer
A chain of custody log must document a complete, unbroken record of every individual who takes possession of evidence. When transferring hardware to a third party, recording the recipient's full name, signature, and the exact timestamp of transfer is mandatory to prove the evidence was safeguarded and untampered with.

Step-by-Step Solution

1
Identify the purpose of a chain-of-custody document
Recognize that chain of custody establishes continuous control and tracking of digital evidence from seizure to courtroom presentation.
Any gap in documentation regarding who handled evidence or when it changed hands can invalidate the evidence in court.
2
Analyze missing elements required during evidence transfer
Determined that handing over physical media to another party requires explicit sign-off by both handler and recipient.
Without the recipient's signature, name, and transfer timestamp, custody control is broken.

Key Concept

Chain of Custody Documentation Requirements
Question 1768Question

A remote user requests interactive help from a corporate IT technician to resolve an application configuration error. The technician needs to view the user's active desktop session and work together with the user while keeping the user's local screen active. Which remote access tool is best suited for this task?

Show answer & explanation

Answer: Microsoft Remote Assistance (MSRA)

Answer

Microsoft Remote Assistance (MSRA)
Microsoft Remote Assistance (MSRA) allows a support technician to connect to a user's active session so both individuals can view the desktop and share control, making it ideal for interactive user assistance.

Step-by-Step Solution

1
Identify the primary requirement of the support scenario.
The technician must interactively view and assist in the user's active session without disconnecting or locking out the local user.
Collaborative desktop troubleshooting requires both the technician and user to see the same screen simultaneously.
2
Evaluate the capabilities of the available remote access tools.
Microsoft Remote Assistance (MSRA) supports interactive desktop sharing where the local user remains connected, whereas Remote Desktop Connection locks the local screen on client Windows editions.
MSRA is designed specifically for user-assisted remote support.

Key Concept

Remote Access Tools and Desktop Sharing Capabilities
Question 1769Question

An IT technician discovers a workstation infected with ransomware on the corporate network. Arrange the initial incident response actions in the correct chronological order from first step to last step.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct sequence of incident response steps is: First, identify the security incident and confirm the threat; Second, report the incident to the designated supervisor or incident response team; Third, isolate the compromised system from the network; Fourth, preserve system evidence and document the chain of custody.
Under standard CompTIA first responder procedures, the chronological order of operations is identification, reporting to proper authorities, isolating the system to contain the threat, and preserving evidence along with chain of custody documentation.

Step-by-Step Solution

1
Identify the incident
Confirmed ransomware infection on the workstation.
Incident identification must occur first to understand the scope and nature of the issue.
2
Report the incident
Escalated details to the security and management team.
Reporting immediately ensures organizational response protocols and communication channels are activated.
3
Isolate the system
The machine is quarantined from the network.
Isolating the system contains the threat and prevents the ransomware from spreading to shared files or other machines.
4
Preserve evidence and document chain of custody
Volatile memory and logs are secured with handler details recorded.
Preserving evidence maintains data integrity and ensures forensic evidence remains admissible and verifiable.

Key Concept

First Responder Incident Response Sequence
Question 1770Question

A technician is preparing to open a desktop PC case to replace a failed RAM module. Which TWO of the following actions should the technician perform prior to handling internal components to ensure personal safety and prevent Electrostatic Discharge (ESD) damage? (Select TWO)

Select all that apply

Show answer & explanation

Answer: Disconnect the AC power cord from the wall outlet or power supply.; Attach an anti-static wrist strap to an unpainted metal surface of the computer chassis.

Answer

The technician should disconnect the AC power cord from the power supply or outlet and attach an anti-static wrist strap to an unpainted metal portion of the computer frame.
Disconnecting the AC power cord ensures electrical safety by cutting off live electrical current. Attaching an anti-static wrist strap to an unpainted metal chassis surface equalizes static electrical charge between the technician's body and the hardware, preventing ESD from damaging sensitive memory modules.

Step-by-Step Solution

1
Ensure physical electrical safety
Removing the AC power cord eliminates active electrical potential and prevents shock hazards while working inside the case.
Safety procedures mandate completely disconnecting power before touching internal hardware.
2
Implement ESD mitigation controls
Clipping an ESD wrist strap onto an unpainted metal surface grounds the technician to the computer chassis, equalizing electrical charges.
Sensitive components like RAM modules are highly vulnerable to damage from low-voltage ESD transfers.

Key Concept

Basic Electrostatic Discharge (ESD) Prevention and Workstation Electrical Safety
Estimated Time:45s
Question 1771Question

A helpdesk technician needs to create a simple script that executes native Windows Command Prompt (cmd.exe) commands to automate workstation login tasks. Which file extension should be assigned to this script?

Show answer & explanation

Answer: .bat

Answer

The .bat extension is used for standard Windows Batch scripts running in the Command Prompt (cmd.exe).
The .bat extension designates a batch file composed of sequential command-line directives designed to be parsed natively by the Windows Command Prompt (cmd.exe).

Step-by-Step Solution

1
Identify the target command environment specified in the scenario.
The scenario requires executing native Windows Command Prompt (cmd.exe) commands.
Script file extensions dictate which interpreter or execution host Windows uses to run the file.
2
Match the Windows Command Prompt environment to its proper file extension.
Windows batch files use the .bat file extension.
The Windows Command Prompt natively interprets and executes files saved with the .bat (or legacy .cmd) extension.

Key Concept

Scripting File Extensions and Runtimes
Question 1772Question

A warehouse quality inspector uses a custom Android-based handheld inventory device. During daily auditing, the proprietary scanning application frequently becomes unresponsive and stops syncing data, although all other system applications and wireless connections continue to operate normally. Following standard least-invasive troubleshooting methodology, which TWO of the following initial actions should the technician perform to resolve the issue?

Select all that apply

Show answer & explanation

Answer: Force stop the inventory application through the mobile OS application settings; Clear the application's temporary cache memory

Answer

The technician should force stop the unresponsive application and clear the application cache.
Force stopping an unresponsive app and clearing its cached memory represent the initial, least-invasive troubleshooting steps for isolated mobile application performance issues. These steps terminate hung threads and remove potentially corrupted temporary files without resetting the OS or deleting persistent app data.

Step-by-Step Solution

1
Isolate the issue scope
Since only the custom scanning application is unresponsive while system connectivity and other apps function normally, the problem is isolated to that specific application process.
Symptom isolation prevents unnecessary global system changes.
2
Apply least-invasive application recovery steps
Force stopping the application terminates hanging process threads, while clearing the app cache removes transient data that may cause application lockups.
Targeted process termination and cache clearing resolve application freezes without data loss.

Key Concept

Least-Invasive Mobile Application Troubleshooting Sequence
Question 1773Question

A tier-2 help desk technician is investigating an enterprise Windows 11 workstation where all installed web browsers (Edge and Chrome) continuously redirect users to an unauthorized site asking for corporate domain credentials when accessing internal or external web applications. The technician observed the following diagnostic details:

- Resetting browser settings, clearing cache/cookies, and starting browsers in safe mode with extensions disabled failed to resolve the issue.
- Automated antivirus and malware scans completed with zero infections detected.
- Standard `ping` requests to domain names resolve to incorrect public IP addresses, even though `ipconfig /all` displays valid corporate internal DNS server IP addresses.
- Running `nslookup company.com` uses the default corporate server and returns the legitimate internal IP address, but browsing directly to `https://company.com` still redirects to the rogue website.

Which of the following root causes is most likely responsible for overriding standard DNS resolution and causing the web browser redirections?

Show answer & explanation

Answer: Unauthorized static mapping entries configured inside the local operating system hosts file

Answer

Unauthorized static mapping entries configured inside the local operating system hosts file
The correct answer identifies unauthorized static mapping entries in the local operating system hosts file (`C:\Windows\System32\drivers\etc\hosts`). Windows evaluates the local `hosts` file prior to sending a query to configured DNS servers. In contrast, the command-line utility `nslookup` directly queries the DNS server, bypassing the local `hosts` file entirely. When `nslookup` yields correct IP addresses while browsers and `ping` commands resolve to malicious IP addresses, it indicates that static entries in the `hosts` file are intercepting and redirecting host name resolution.

Step-by-Step Solution

1
Analyze name resolution behavior differences between browser requests/ping and `nslookup`.
Identified that `ping` and web browsers use the standard Windows Name Resolution order (which checks the local `hosts` file before querying DNS), whereas `nslookup` queries the configured DNS server directly by design.
When `nslookup` returns the correct IP but browsers resolve to a rogue IP, the discrepancy points to a local override mechanism that precedes DNS server resolution in the OS lookup stack.
2
Evaluate local system components capable of overriding DNS name resolution.
The Windows `hosts` file located at `C:\Windows\System32\drivers\etc\hosts` maps hostnames directly to IP addresses and is evaluated before network DNS queries.
Malware or unauthorized scripts frequently modify the `hosts` file to redirect web requests away from legitimate servers to attacker-controlled IP addresses.
3
Formulate remediation steps.
Inspect and clean the `hosts` file by removing unauthorized static IP-to-hostname mappings.
Clearing malicious lines from the `hosts` file restores standard DNS lookup ordering and stops browser redirects.

Key Concept

Browser Redirect Troubleshooting and Windows Name Resolution Hierarchy
Question 1774Question

An IT technician is dispatched to perform hardware maintenance on a commercial high-volume laser printer that recently experienced a major internal toner spill and high-voltage power fault. Which TWO of the following safety and environmental procedures must the technician implement to safely complete this repair?

Select all that apply

Show answer & explanation

Answer: Allow the printer's fuser assembly to cool down fully prior to handling internal components to prevent severe thermal burns.; Use a specialized electrostatic-discharge (ESD) safe vacuum equipped with a fine particulate HEPA filter rather than a standard vacuum cleaner to clean toner dust.

Answer

The technician must allow the printer's fuser assembly to cool down completely before touch or removal to avoid thermal burn injuries, and use a dedicated ESD-safe toner vacuum with HEPA filtration to clean spilled toner particles safely.
Laser printer maintenance presents specific physical hazards: fuser units reach extreme temperatures requiring time to cool to prevent thermal burns, while spilled toner consists of ultrafine conductive particles that require specialized ESD-safe vacuums with HEPA filters to avoid airborne dispersion, static ignition, and hardware damage.

Step-by-Step Solution

1
Identify high-temperature hardware components before touching internal printer assemblies.
Recognized that the fuser unit maintains extreme thermal energy and requires cooling down time to ensure technician safety.
Prevent severe skin burns from components operating above 200°C.
2
Evaluate proper cleanup tools for microscopic toner powder.
Selected an ESD-safe vacuum featuring HEPA filters designed specifically for toner dust.
Standard vacuums create static electricity that can ignite toner dust clouds and blow fine toxic particulates back into the breathing environment.
3
Review proper disposal and ESD grounding safety protocols.
Rejected unsafe grounding practices to live AC lines and illegal incineration procedures for chemical waste.
Ensures adherence to CompTIA A+ environmental guidelines and personal electrical safety.

Key Concept

Laser Printer Thermal and Environmental Safety Practices
Question 1775Question

A system administrator resolves an issue where workstations in a remote branch office were failing to obtain authentications from a newly migrated domain controller due to misconfigured subnets in Active Directory Sites and Services. After correcting the site bindings and verifying connectivity, the administrator must complete the ticket lifecycle. Which of the following documentation actions are required before closing the support ticket? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Log the specific root cause, network configuration changes made, and verification test results in the ticket's internal resolution notes.; Update the Configuration Management Database (CMDB) to associate the updated domain controller subnet mappings with the remote branch site asset records.

Answer

Proper ticketing workflow requires logging the complete technical resolution notes (including root cause and verification steps) and updating infrastructure dependencies in the CMDB before obtaining user sign-off and closing the ticket.
Correct ticket workflow standards dictate that technicians log comprehensive resolution entries (including the root cause, steps taken, and confirmation testing) and update associated asset management database (CMDB) records to reflect configuration updates.

Step-by-Step Solution

1
Analyze technical documentation requirements for ticketing lifecycle completion.
Identified that comprehensive work logs (root cause, remediation steps, verification) are mandatory for resolution logging.
Capturing full technical details prevents duplicate effort on recurring issues and maintains an accurate audit trail.
2
Evaluate asset management and CMDB workflow integration.
Identified that site subnet reassignments must reflect in the asset management database attached to the ticket.
Maintaining synchronized CMDB infrastructure records ensures operational documentation reflects current environment configurations.
3
Identify improper ticketing procedures in distractors.
Rejected options that overwrite original user input or bypass end-user confirmation prior to closure.
Preserving the original submission preserves audit integrity, and user confirmation verifies actual issue resolution.

Key Concept

Complete Incident Documentation and Ticket Resolution Workflows
Question 1776Question

A tier-2 systems technician is configuring network access and security rules for an administrator who needs to perform secure, encrypted command-line management on a remote Linux server located behind a corporate firewall. Which of the following protocols and standard transport layer port numbers must be enabled on the firewall to allow this access? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: SSH (Secure Shell); TCP port 22

Answer

The correct selections are SSH (Secure Shell) and TCP port 22.
SSH (Secure Shell) combined with TCP port 22 satisfies both requirements: establishing an encrypted command-line connection to a remote server and permitting the necessary network traffic through the perimeter firewall.

Step-by-Step Solution

1
Identify the remote access interface requirement
The scenario calls for a secure, encrypted text-based command-line interface to manage a Linux server.
Linux administration typically relies on command-line utilities, which must be encrypted when accessed across external networks.
2
Select the appropriate remote access protocol
SSH (Secure Shell) is selected over Telnet because Telnet transmits data in plain text without encryption.
SSH encrypts all traffic, including authentication credentials and terminal output.
3
Identify the default TCP port for the chosen protocol
SSH operates over TCP port 22 by default.
Firewall rules must permit inbound traffic on TCP port 22 to allow the SSH daemon on the target server to accept connections.

Key Concept

Remote Command-Line Security Protocols and Default Ports
Question 1777Question

A remote desktop technician is connected to an end user's system via an authorized screen-sharing session to troubleshoot an email profile error. During the session, the user receives an urgent phone call and steps away from their desk, leaving a sensitive spreadsheet containing unencrypted Personally Identifiable Information (PII) open on the display. Which of the following actions should the technician take to uphold data privacy and professional communication standards? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Refrain from inspecting, copying, or altering the sensitive file visible on the display.; Pause the remote control session stream until the user returns to their workstation.

Answer

The technician should refrain from inspecting, copying, or altering sensitive files on display, and pause the remote control session stream until the user returns.
When sensitive or confidential information is exposed during a support session, professional guidelines dictate respecting customer privacy by avoiding any inspection or alteration of the data, and pausing active remote viewing streams until the user returns to control their environment.

Step-by-Step Solution

1
Assess the remote environment upon the user stepping away.
Identify that confidential data (PII) is exposed on the unattended remote screen.
Technicians must constantly maintain awareness of customer privacy and security boundaries during remote sessions.
2
Protect user privacy by restricting unauthorized viewing and interaction.
Pause the remote control stream and avoid reading, copying, or changing the open file.
Pausing remote viewing prevents unauthorized exposure of data, while avoiding file interaction preserves data integrity and respects user property.

Key Concept

Customer Privacy and Ethical Boundaries in Remote Sessions
Question 1778Question

A desktop technician is troubleshooting a Windows workstation displaying missing file errors and system instability. The technician suspects corruption within both the Windows component store and protected operating system files. In what order should the technician perform the following repair steps to ensure system integrity is fully restored?

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct sequence of repair steps is: Open an elevated Command Prompt, execute DISM to repair the component store, execute SFC to repair system files, and restart the computer to complete pending replacements.
To repair corrupted operating system files effectively, administrative elevation must be established first. Executing DISM `/restorehealth` restores the health of the Windows component store image. Once the store is repaired, running `sfc /scannow` allows the System File Checker to successfully extract clean file copies from the component store and repair corrupted OS files. Finally, restarting the workstation applies file updates for core binaries that were locked in active memory during the scan.

Step-by-Step Solution

1
Open Command Prompt with administrative privileges.
Obtains necessary administrative permissions to run system-level diagnostic and repair tools.
Both DISM and SFC require elevated privilege levels to modify protected system directories.
2
Run `dism /online /cleanup-image /restorehealth`.
Scans and repairs the Windows image component store cache.
The System File Checker uses the component store as its source repository. If the component store itself is corrupt, SFC will fail to repair files until DISM fixes the store.
3
Run `sfc /scannow`.
Scans protected system files and replaces corrupted ones using the restored component store.
Once the component store is healthy, SFC can pull clean replacement files to replace damaged system binaries.
4
Reboot the operating system.
Applies changes to system files that could not be modified while actively loaded in memory.
Core operating system files in active use are queued for replacement during the next system startup.

Key Concept

Sequential repair of Windows component store using DISM prior to executing System File Checker (SFC)
Estimated Time:1m 30s
Question 1779Question

A field technician is called to secure a finance manager's workstation that was infected with ransomware via a suspicious email link. The technician immediately isolates the workstation from the corporate network and captures a forensic image of volatile memory. To ensure all evidence remains legally admissible, the technician prepares to transfer the physical workstation to the enterprise forensics team. Which of the following details MUST be documented on the chain of custody form during this transfer?

Show answer & explanation

Answer: The date, time, unique device serial numbers, and the signatures of both the transferring technician and receiving investigator

Answer

The date, time, unique device serial numbers, and the signatures of both the transferring technician and receiving investigator must be documented on the chain of custody form during the transfer.
Chain of custody documentation provides an unbroken chronological record tracking the acquisition, transfer, analysis, and disposition of physical and digital evidence. Whenever evidence changes hands, the log must capture the date, time, exact item description and serial number, location, and the verified signatures of both the individual surrendering the evidence and the individual receiving it.

Step-by-Step Solution

1
Identify the core purpose of chain of custody documentation in forensic procedures.
Chain of custody establishes a continuous, legally defensible audit trail showing who possessed, secured, or transferred physical and digital evidence at every point in time.
If custody cannot be proven unbroken, evidence may be deemed tampered with or inadmissible in legal proceedings.
2
Identify mandatory fields required during an evidence custody transfer.
The log must record the precise date and time of transfer, detailed description and serial numbers of the item, location details, and the full names and signatures of both the releasing party and receiving party.
This establishes clear responsibility and accountability for the evidence at the exact moment of transfer.
3
Evaluate the choices against chain of custody logging standards.
Recording timestamps, hardware identifiers, and signatures of both parties satisfies the formal chain of custody requirements.
Passwords, building physical barrier specifications, and malware classification taxonomies do not fulfill evidence tracking requirements.

Key Concept

Chain of Custody Documentation Requirements
Question 1780Question

An employee reports that their corporate-managed smartphone suddenly cannot access internal enterprise email servers while connected to cellular data, though public websites load without issue. A technician verifies that the cellular carrier network is fully operational. Which of the following is the most likely cause of this access restriction?

Show answer & explanation

Answer: An expired or corrupted enterprise MDM security profile on the device

Answer

An expired or corrupted enterprise MDM security profile on the device
Mobile Device Management (MDM) security profiles enforce access rules and store identity certificates required to authenticate to enterprise email servers. If the profile expires or becomes corrupted, the device is restricted from corporate resources, even though general internet connectivity over cellular data remains functional.

Step-by-Step Solution

1
Analyze the reported symptoms and network scope
General internet traffic functions normally over cellular data, but access to internal enterprise email resources is blocked.
Determining whether connectivity issues affect all network traffic or only corporate services isolates device security profile issues from carrier outages.
2
Evaluate potential root causes specific to enterprise service access
Corporate email authentication relies on valid Mobile Device Management (MDM) configuration profiles and security certificates.
If an MDM profile expires or becomes corrupted, corporate access control policies block access to enterprise resources.

Key Concept

Troubleshooting Mobile OS MDM Security Profiles and Corporate Resource Connectivity
Estimated Time:1m 0s
PreviousPage 89 / 178Next
All practice questions — CompTIA A+ (Core 1 & Core 2) | Examkin