All practice questions

786 questions

Question 1Question

A network technician is diagnosing connectivity issues in a manufacturing facility. Mobile Wi-Fi terminals roaming across 2.4 GHz access points experience frequent packet loss and drops, with an audit showing access points currently configured to channels 1, 3, and 6. Meanwhile, a newly installed wired desktop receives an APIPA address of 169.254.14.22 and cannot reach local server resources. Which TWO of the following actions should the technician take to resolve these issues?

Select all that apply

Show answer & explanation

Answer: Reconfigure the 2.4 GHz wireless access points to use non-overlapping channels (1, 6, and 11).; Verify physical Ethernet link lights on the desktop network card and troubleshoot DHCP server reachability.

Answer

The technician should reconfigure the 2.4 GHz wireless access points to use non-overlapping channels (1, 6, and 11) to resolve signal interference, and check physical link lights and DHCP server reachability to resolve the APIPA address assignment on the wired desktop.
Reconfiguring 2.4 GHz access points to non-overlapping channels (1, 6, and 11) eliminates channel interference causing Wi-Fi packet drops. Checking physical link lights and DHCP reachability addresses the root cause of the workstation receiving an APIPA address (169.254.x.x) due to unacknowledged DHCP discovery.

Step-by-Step Solution

1
Resolve 2.4 GHz wireless channel interference
Reconfiguring access points to use channels 1, 6, and 11 removes adjacent-channel interference and prevents packet loss during roaming.
Channels 1, 3, and 6 overlap in the 2.4 GHz spectrum, causing co-channel interference.
2
Diagnose wired network APIPA assignment
Verifying physical link indicators and inspecting DHCP server/relay configuration identifies why the client cannot acquire a valid dynamic IP address.
An address in the 169.254.0.0/16 range signifies that the operating system self-assigned an APIPA address because no DHCP server responded.

Key Concept

Resolving 2.4 GHz wireless channel overlap interference and wired client APIPA reachability failures.
Question 2Question

A video editing workstation utilizes a two-drive software RAID 1 array for local project scratch space. During a rendering session, the system experiences severe input/output latency, and the operating system logs several disk read error events. Physical inspection reveals a high-pitched metallic clicking sound coming from one of the mechanical hard drives. Disk Management shows the volume status as Degraded, with Disk 1 marked as Offline/Errors, while Disk 0 remains Online and operational. Which TWO of the following actions should the technician take to restore full system redundancy while mitigating the risk of data loss?

Select all that apply

Show answer & explanation

Answer: Immediately back up all critical files from the degraded volume on Disk 0 to a separate external or network location.; Replace Disk 1 with a new drive of equal or greater capacity, then initiate a volume rebuild using Disk Management.

Answer

The technician should immediately back up critical data from the surviving drive (Disk 0) to an external or network location and then replace the failed drive (Disk 1) with a drive of equal or greater capacity to rebuild the array.
When a RAID 1 array becomes degraded due to a mechanical failure in one disk, the surviving disk contains all original data. First backing up the surviving disk guards against total data loss if the healthy disk fails under heavy load during reconstruction. Second, physically replacing the clicking, failed disk with a known-good disk of equal or higher capacity followed by initiating a software rebuild restores fault tolerance without losing existing data.

Step-by-Step Solution

1
Diagnose the hardware failure based on symptoms.
Identified physical mechanical failure (clicking sound, read errors) on Disk 1 causing a degraded RAID 1 state.
Recognizing physical hard drive failure isolates the faulty component from the surviving healthy mirror disk (Disk 0).
2
Perform a fresh backup of the active volume.
Critical files are secured on external or secondary storage.
Rebuilding a degraded array subjects the surviving drive to heavy read activity, increasing the risk of a secondary failure during recovery.
3
Replace the failed physical drive and execute a volume rebuild.
Disk 1 is swapped with a healthy drive of equal or greater capacity, and data is resynchronized from Disk 0.
RAID 1 redundancy is fully restored only after replacing the defective disk and completing the mirror synchronization process.

Key Concept

RAID 1 Degraded State Recovery & Data Preservation Procedures
Question 3Question

A user brings a 2-in-1 touchscreen laptop to the help desk reporting two issues. First, the trackpad is lifting away from the chassis and the battery rapidly loses charge, despite the user repeatedly running deep discharge cycles to 0% to recalibrate it. Second, when the user connects a dual-monitor docking station to a standard USB Type-C port on the side of the laptop, the external displays show no image signal. Which of the following statements or troubleshooting steps correctly address these issues? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Safely remove and properly dispose of the bulging battery immediately, as deep discharging lithium-ion cells increases damage and poses a safety hazard.; Verify that the external docking station is connected to a USB-C port that explicitly supports DisplayPort Alternate Mode or Thunderbolt protocols.

Answer

The technician should safely remove and dispose of the swollen battery immediately, and verify that the docking station is connected to a USB-C port supporting DisplayPort Alternate Mode or Thunderbolt.
The correct responses recognize that a swollen battery must be immediately decommissioned and replaced due to safety risks, and that external monitor output over USB Type-C requires a port with DisplayPort Alternate Mode or Thunderbolt controller support.

Step-by-Step Solution

1
Address the swollen battery symptom.
Identify physical trackpad lifting as battery swelling in lithium-ion cells.
Swollen lithium-ion batteries pose a fire safety hazard. Continuing deep discharge cycles worsens degradation.
2
Address the external video output failure over USB-C.
Determine port capability differences.
USB Type-C is a connector form factor. Display output requires host controller support for DisplayPort Alt Mode or Thunderbolt.

Key Concept

Mobile Device Battery Safety & USB-C Display Protocol Requirements
Estimated Time:2m 0s
Question 4Question

A desktop technician is troubleshooting a corporate network multifunction laser printer. Users report two specific complaints: all printed documents display continuous vertical black streaks down the length of every page, and scans created using the Automatic Document Feeder (ADF) exhibit a thin vertical black line along the edge of the digitized image, whereas scans placed directly on the flatbed glass are entirely clear. Which TWO of the following actions should the technician perform to resolve these distinct issues?

Select all that apply

Show answer & explanation

Answer: Clean the small ADF glass strip adjacent to the main flatbed glass using a lint-free cloth.; Inspect and replace the photosensitive drum assembly or drum cleaning blade.

Answer

The technician should clean the narrow ADF glass strip to resolve the ADF scanning line, and inspect or replace the photosensitive drum assembly to resolve the vertical printing streaks.
Cleaning the narrow ADF glass strip eliminates debris that causes vertical lines on ADF scans (since flatbed glass scans are clear). Replacing or cleaning the photosensitive drum assembly addresses continuous vertical black lines across all printed jobs caused by drum surface damage or cleaning blade failure.

Step-by-Step Solution

1
Analyze the scanning symptom difference between ADF and flatbed modes.
Since flatbed scans are clean while ADF scans have a line, the issue is isolated to debris or white-out on the narrow ADF scanner glass strip where the document moves over a stationary optical sensor.
ADF scanning moves paper past a fixed glass slit, so any speck on that glass creates a solid line down the scanned page.
2
Analyze the printing symptom involving vertical black lines on output.
Identify that excess toner is remaining on the photosensitive drum during the printing cycle due to a damaged cleaning blade or scratched drum cylinder surface.
A defect in the drum or cleaning blade causes toner to build up in a line, transferring directly onto paper during the transfer phase.

Key Concept

Multifunction printer optic diagnostics (ADF glass vs flatbed) and electrophotographic printing defects.
Estimated Time:2m 0s
Question 5Question

A technician is setting up a dual-monitor workstation connected to a corporate laptop through a single USB-C docking station using DisplayPort Multi-Stream Transport (MST). The primary monitor operates normally at full resolution, but the second daisy-chained monitor displays an incorrect low resolution and suffers from intermittent screen flickering. Which of the following potential root causes or initial troubleshooting steps should the technician evaluate to address these symptoms? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: The combined resolution and refresh rate of both monitors exceed the total video bandwidth available over the single USB-C DisplayPort Alt Mode connection.; DisplayPort MST mode is disabled in the OSD settings of the primary monitor or unsupported by the current graphics driver configuration.

Answer

The technician should verify that the combined monitor resolution does not exceed the USB-C DisplayPort Alt Mode bandwidth limit and ensure that DisplayPort MST mode is properly enabled in the monitor OSD and supported by the graphics driver.
DisplayPort Multi-Stream Transport (MST) requires both adequate cable/interface bandwidth and proper configuration. If the total pixel bandwidth of all connected displays exceeds the USB-C DisplayPort Alt Mode capacity, secondary monitors drop in resolution or suffer signal loss. Additionally, MST must be explicitly enabled in the monitor's OSD configuration and supported by driver software to route separate video signals.

Step-by-Step Solution

1
Analyze the physical and logical display connection topology.
The topology relies on DisplayPort Multi-Stream Transport (MST) over a single USB-C Alt Mode link.
MST enables multiplexing independent display streams over a single cable path, but total bandwidth is strictly bounded by the USB-C lanes dedicated to video.
2
Evaluate bandwidth limitations of the host interface.
Running multiple high-resolution displays exceeds total link bandwidth, causing secondary screens to fallback to lower resolutions or flicker.
Lowering resolution or refresh rate on the primary monitor frees required bandwidth for the secondary screen.
3
Verify protocol configuration on display hardware.
Disabling MST in monitor OSD defaults the connection to Single-Stream Transport (SST), mirroring displays or disabling the downstream port.
Enabling MST in the monitor settings enables proper stream routing across daisy-chained links.

Key Concept

DisplayPort Multi-Stream Transport (MST) and USB-C Video Bandwidth Troubleshooting
Question 6Question

An IT support technician is troubleshooting a network multifunction device (MFD) in an office department. Users report two distinct issues: double-sided print jobs consistently jam in the paper-reversing area before printing the second side, and multi-page documents scanned using the Automatic Document Feeder (ADF) show a continuous vertical line down every page, although flatbed scans produce completely clear images. Which TWO of the following actions should the technician perform to address these issues?

Select all that apply

Show answer & explanation

Answer: Clean the narrow ADF glass strip located adjacent to the main flatbed glass.; Inspect and replace the worn duplexing unit rollers and paper direction gates.

Answer

The technician should clean the narrow ADF glass strip to resolve the scanning lines and inspect or replace the worn duplexing unit rollers to fix double-sided paper jams.
Continuous vertical lines on ADF-scanned documents indicate foreign matter on the small ADF glass strip where paper passes over the stationary reader sensor. Cleaning this glass removes the line artifact. Jams occurring strictly when flipping paper for double-sided output indicate worn feed rollers or damaged divert flaps in the duplexing assembly.

Step-by-Step Solution

1
Diagnose the ADF scanning defect symptom
Identify that vertical lines occurring only during feeder scans (and not on flatbed scans) are caused by stationary debris on the narrow ADF scanner glass strip as paper slides over it.
Because paper moves past a fixed optical glass strip during ADF scanning, any foreign material on that glass creates a continuous vertical streak across the length of every page.
2
Diagnose the duplex paper jam symptom
Isolate the failure to the duplexer reversing path and rollers, which are engaged only when flipping paper for two-sided output.
Single-sided jobs bypass the reversing section, confirming that standard feed rollers function properly and that the issue lies specifically within the duplexing mechanism.

Key Concept

Multifunction device ADF glass optical maintenance and duplexing paper path troubleshooting
Question 7Question

A technician is troubleshooting a high-performance workstation PC that fails to complete the Power-On Self-Test (POST). When pressing the power button, the system chassis fans turn on at maximum speed, but no video display signal is output, no POST diagnostic beep codes are produced by the motherboard speaker, and the onboard debug LED stays permanently frozen on the CPU initialization state code (00). Which of the following initial diagnostic procedures should the technician perform to isolate the underlying hardware failure? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Reseat the central processing unit (CPU) and inspect the motherboard socket pins for bends or thermal paste contamination.; Perform a bare-bones bench test outside the chassis using only the motherboard, CPU, power supply, and a single memory module.

Answer

The technician should reseat the CPU while inspecting the socket pins and execute a minimal bare-bones bench test outside the chassis.
The correct troubleshooting steps focus on early pre-POST failure resolution: checking physical CPU seating and socket pin integrity, and removing the motherboard from the metal chassis to eliminate ground shorts while testing only fundamental core hardware.

Step-by-Step Solution

1
Analyze the observed system failure indicators
System experiences a hardware pre-POST halt; fans spin at full speed, debug LED freezes on CPU state (00), and no POST beep codes are produced.
Indicates the failure occurs before firmware handoff to RAM or video initialization, placing the primary fault on CPU seating/socket, power delivery, or motherboard grounding.
2
Isolate CPU hardware interface issues
Reseating the CPU ensures even mounting pressure, correct socket pin contact, and lack of socket damage.
Damaged pins or misaligned CPU contact pads prevent basic microcode execution required to progress past debug code 00.
3
Eliminate chassis shorts and peripheral interference
Disconnect all unnecessary peripherals and remove the motherboard from the chassis for bench testing.
A metallic standoff shorting the motherboard or a shorted expansion card can cause the power supply or motherboard logic to latch into a pre-POST CPU lock state.

Key Concept

Pre-POST Hardware Fault Isolation and CPU Diagnostic Troubleshooting
Question 8Question

A remote employee reports that after upgrading their corporate laptop software, they can browse external websites but can no longer access local network shares over the company VPN. An IT support specialist has already duplicated the problem on a test machine, confirmed the symptoms, and verified that no central network maintenance was performed. According to the CompTIA 6-step troubleshooting methodology, which of the following actions should the specialist perform NEXT to establish a theory of probable cause? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Inquire whether any local configuration settings or client permissions were changed during the software upgrade.; Search internal knowledge bases and software documentation for known compatibility bugs related to the new client build.

Answer

The technician should inquire about recent local configuration changes and research knowledge base documentation for known software compatibility issues.
According to the CompTIA troubleshooting methodology, after identifying the problem and questioning environmental changes, the technician must establish a theory of probable cause. Inquiring about local configuration changes and searching knowledge bases for documented software bugs are standard methods to form a valid theory.

Step-by-Step Solution

1
Identify current troubleshooting stage
The technician has already identified symptoms and confirmed the issue, placing them in Step 1 (Identify the problem).
The next logical step in the CompTIA 6-step troubleshooting methodology is Step 2: Establish a theory of probable cause.
2
Select actions appropriate for Step 2 (Theory of Probable Cause)
Questioning internal/external changes (local software settings) and conducting research (knowledge base lookups) belong to this stage.
Establishing a theory requires considering both simple causes, recent changes, and known issues.

Key Concept

CompTIA 6-Step Troubleshooting Methodology - Establishing a Theory of Probable Cause
Estimated Time:1m 30s
Question 9Question

A support technician is troubleshooting a legacy LCD touchscreen laptop after a user reported that the display screen is extremely dark and touch inputs register several inches away from where the user presses. The technician can barely see desktop icons when shining a bright flashlight directly at the glass panel. Which TWO of the following underlying hardware issues or corrective actions are most appropriate for this scenario? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: The LCD display backlight inverter board or CCFL lighting element has failed and requires replacement.; The touch screen digitizer needs software recalibration or its ribbon cable needs to be reseated.

Answer

The correct options are that the LCD display backlight inverter board or CCFL lighting element has failed, and the touch screen digitizer requires software recalibration or ribbon cable reseating.
When an LCD mobile screen displays a faint image under direct light, the issue is isolated to the backlight system, such as a failed inverter board or CCFL tube. Additionally, touch inputs registering away from the touch location indicate that the digitizer requires software recalibration or physical cable reseating.

Step-by-Step Solution

1
Diagnose the dark screen symptom using the flashlight test.
Confirming visible desktop graphics under external light isolates the problem to the LCD backlight assembly or inverter board rather than the graphics processing unit or main LCD matrix.
CCFL backlights in traditional mobile LCD displays require high-voltage AC current supplied by an inverter board.
2
Address the misaligned touch input symptom.
Recalibrating the digitizer via OS software utilities or inspecting the physical digitizer ribbon connection restores proper coordinate mapping for touch inputs.
The digitizer converts tactile touches into spatial coordinates; hardware misalignments or loose ribbon traces cause input offsets.

Key Concept

Mobile LCD Backlight Inverter Diagnosis and Digitizer Calibration
Estimated Time:1m 30s
Question 10Question

A system deployment specialist is preparing a computer for a software developer who requires native local virtual machine hosting and full-volume drive encryption to safeguard confidential source code. The computer currently runs Windows 11 Home. Which TWO of the following features require upgrading the system to Windows 11 Pro or higher to become available? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Client Hyper-V hypervisor management; BitLocker Drive Encryption

Answer

Client Hyper-V hypervisor management and BitLocker Drive Encryption are the features that require upgrading from Windows 11 Home to Windows 11 Pro or higher.
Client Hyper-V hypervisor management and BitLocker Drive Encryption are advanced administrative and enterprise-grade security features exclusive to Windows 11 Pro, Enterprise, and Education editions. To fulfill the requirements for local virtual machine hosting and full-volume encryption, the operating system must be upgraded from Windows Home to Windows Pro or higher.

Step-by-Step Solution

1
Analyze the technical requirements in the scenario
Identified two primary feature requirements: native local virtual machine hosting and full-volume drive encryption.
Determining exact operational needs is necessary to check Windows edition feature matrices.
2
Evaluate feature availability in Windows 11 Home edition
Windows 11 Home does not support Client Hyper-V or full BitLocker Drive Encryption.
Microsoft restricts corporate management and virtualization tools to Pro and higher editions.
3
Identify non-restricted features included in Windows 11 Home
Storage Spaces and Windows Defender Firewall are present and functional in Windows 11 Home.
Basic storage management and host firewall protection are standard features across all desktop editions.

Key Concept

Windows OS Edition Feature Boundaries
Question 11Question

A technician is troubleshooting a newly built desktop workstation that powers on, but fails to complete POST or display video output. The system fans run at continuous maximum speed, and the diagnostic status LED on the motherboard remains illuminated red on the CPU indicator. Which of the following are the MOST appropriate initial troubleshooting steps to perform? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Verify that the 8-pin EPS +12V power connector is securely plugged into the motherboard near the CPU.; Remove the CPU cooler to inspect for bent socket pins and verify proper seating.

Answer

Verifying the 8-pin EPS power connection and inspecting the CPU socket for bent pins or improper mounting are the correct diagnostic steps.
When a computer powers on with continuous high-speed fans and a lit CPU diagnostic LED without completing POST, the issue stems from power delivery or physical connectivity to the CPU. Confirming that the 8-pin EPS cable is connected supplies necessary power to the processor VRMs. Inspecting the socket for bent LGA pins ensures physical electrical continuity across all land pads.

Step-by-Step Solution

1
Identify the symptoms
System powers on with max fan speed, no POST/video, and a solid red CPU diagnostic LED.
Indicates hardware failure specifically during early CPU initialization prior to POST completion.
2
Check power delivery to the CPU
Ensure the 8-pin EPS 12V connector from the power supply is firmly latched to the motherboard socket.
Without dedicated 12V CPU power, the processor cannot initialize even though the main 24-pin ATX power supply feeds motherboard standby/fan headers.
3
Inspect CPU physical installation
Remove heatsink/fan assembly, open socket retention arm, and check LGA pins.
Damaged or bent pins prevent signals between motherboard chipsets and CPU, leading to persistent POST halt on CPU diagnostic check.

Key Concept

CPU POST Diagnostics and Auxiliary Power Connection Isolation
Question 12Question

A systems administrator is configuring the deployment of a custom enterprise application on 64-bit Windows 11 workstations. The setup executable registers a background system service during installation, and the application writes shared runtime configurations to a local directory. Standard non-administrative users must be able to launch the application and update its configuration without experiencing User Account Control (UAC) prompts or access denied errors. Which of the following steps should the administrator take to properly deploy and configure this application? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Execute the application installer using an administrative account context to permit service registration during setup.; Configure local file system access control lists (ACLs) to grant standard users Modify permissions on the application's dedicated subfolder inside %ProgramData%.

Answer

The administrator must execute the installer under an administrative account context to allow service registration, and grant standard users Modify permissions on the application's dedicated subfolder within %ProgramData%.
Installing software that registers system-level services requires administrative elevation to modify protected Windows components. To allow standard users to read and write shared configuration files without elevating their privileges or modifying protected %ProgramFiles% permissions, the administrator should adjust access control lists (ACLs) to grant Modify permissions specifically on the application's folder under %ProgramData%.

Step-by-Step Solution

1
Analyze installation requirements for background service registration.
Registering Windows services requires modifying protected system configuration areas, necessitating administrative elevation.
Standard user accounts lack rights to create or modify system services.
2
Evaluate storage locations for user-editable shared application settings.
%ProgramData% is the proper location for shared application state, but standard users require explicit Modify permissions on the app's specific subfolder.
Standard users have read-only access to %ProgramFiles% and default %ProgramData% locations, so granting localized ACL rights prevents permission errors while maintaining principle of least privilege.
3
Evaluate and eliminate incorrect distractor actions.
Compatibility Mode and /quiet CLI switches do not bypass security boundaries or elevate privileges for non-administrative accounts.
Security controls like UAC and file system ACLs cannot be bypassed using installer UI switches or legacy compatibility shims.

Key Concept

Application installation administrative elevation and least-privilege folder permission configuration
Question 13Question

A security technician at a defense contractor is investigating a multi-stage security incident reported across the corporate facility. Physical access logs and security footage show an unknown individual wearing a fake delivery uniform closely following an authorized employee through a badge-restricted turnstile without scanning an access card. Later that day, several senior lead engineers received customized emails containing authentic project reference numbers and names of their team members, requesting that they click an external link to verify their corporate credentials. Which of the following social engineering threat types were directly executed during this incident? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Tailgating; Spear phishing

Answer

The attack involved Tailgating (unauthorized physical entry by following an employee) and Spear Phishing (highly customized email targeting specific engineers).
The scenario describes two distinct threat vectors: physical entry achieved by closely following an authorized badged user through a security turnstile (Tailgating), and an electronic attack utilizing customized internal project references sent to specific senior staff members to harvest credentials (Spear Phishing).

Step-by-Step Solution

1
Analyze the physical access breach described in the scenario.
The intruder wearing a delivery uniform closely followed a badged employee through a restricted turnstile without presenting credentials.
This physical social engineering technique of entering restricted areas behind authorized personnel is defined as tailgating.
2
Analyze the digital attack vectors presented in the incident report.
Selected senior lead engineers received tailored emails with internal project names and coworker information designed to steal credentials.
Targeted, customized electronic messages directed at specific key individuals inside an organization represent spear phishing rather than broad phishing.
3
Differentiate and eliminate non-matching social engineering attack types.
Vishing requires phone interaction, dumpster diving requires searching trash receptacles, and shoulder surfing requires direct visual monitoring of screens.
None of these secondary vectors were indicated in the security footage or email log evidence.

Key Concept

Identifying Physical and Digital Social Engineering Vectors
Estimated Time:2m 0s
Question 14Question

A system administrator is configuring security baselines on standalone Windows 11 Pro workstations located in a shared laboratory environment. To enforce strict access controls and prevent standard domain users from triggering administrative privilege requests or running unauthorized installers, the administrator opens the Local Security Policy snap-in (secpol.msc). Which TWO User Account Control (UAC) policy settings should the administrator configure under Security Options? Select TWO.

Select all that apply

Show answer & explanation

Answer: Set 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests'; Set 'User Account Control: Detect application installations and prompt for elevation' to 'Enabled'

Answer

The administrator should configure 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' and set 'User Account Control: Detect application installations and prompt for elevation' to 'Enabled'.
Configuring 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' prevents standard users from receiving credential prompts during elevation attempts. Setting 'User Account Control: Detect application installations and prompt for elevation' to 'Enabled' ensures software installation routines trigger UAC evaluation.

Step-by-Step Solution

1
Identify the proper snap-in for configuring User Account Control security baselines
Local Security Policy (secpol.msc) under Security Options houses granular UAC policy settings.
System-wide UAC elevation and detection policies are managed via local security options.
2
Select the policy setting that suppresses elevation prompts for standard accounts
Setting 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' prevents standard users from seeing credential prompts.
This automatically blocks privilege elevation attempts by non-administrative users.
3
Select the policy setting that monitors software installer executions
Enabling 'User Account Control: Detect application installations and prompt for elevation' causes Windows to detect setup programs and require elevation.
This prevents unauthorized applications from making silent or unapproved system modifications.

Key Concept

Windows User Account Control (UAC) Security Options in Local Security Policy (secpol.msc)
Question 15Question

A Windows 11 desktop computer is experiencing persistent connectivity issues following a router migration. A help desk technician needs to purge the local DNS resolver cache to remove stale IP address mappings and reset the IPv4 protocol stack to its default state to resolve protocol stack corruption. Which of the following commands should the technician execute on the client machine? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: ipconfig /flushdns; netsh int ip reset

Answer

The technician must execute `ipconfig /flushdns` to purge stale host name records from the local resolver cache and `netsh int ip reset` to restore the TCP/IP protocol stack to its clean default configuration.
Executing `ipconfig /flushdns` flushes obsolete address entries stored in the local client cache. Executing `netsh int ip reset` resets the TCP/IP interface stack by overwriting registry keys controlling network protocols, resolving protocol layer corruption.

Step-by-Step Solution

1
Identify the command required to clear cached local DNS resolver entries.
The `ipconfig /flushdns` command empties the local DNS cache so the client performs fresh DNS queries.
Outdated host-to-IP mappings cause routing failure to local or remote host names after router reconfigurations.
2
Identify the command required to reset the TCP/IP stack configuration.
Executing `netsh int ip reset` rewrites registry keys controlling TCP/IP settings to defaults.
Protocol stack corruption prevents stable socket operations, requiring a reset of the network stack.

Key Concept

Windows Network Command-Line Diagnostics and Repair
Question 16Question

A security administrator is hardening standalone Windows 11 Professional workstations deployed in a public testing center. To adhere to compliance guidelines, standard user accounts must be strictly prohibited from triggering administrator credential prompts upon attempting elevated tasks, and any executable requesting administrative privileges must be verified against a valid digital signature infrastructure before elevation is permitted. Which TWO settings in Local Security Policy (secpol.msc) under Security Options should the administrator configure to meet these requirements? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Set 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests'; Set 'User Account Control: Only elevate executables that are signed and validated' to 'Enabled'

Answer

The administrator must set 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' and set 'User Account Control: Only elevate executables that are signed and validated' to 'Enabled'.
Configuring 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' suppresses administrator credential prompts for non-admin accounts and rejects the operation. Additionally, enabling 'User Account Control: Only elevate executables that are signed and validated' mandates that any executable requesting administrative privileges must pass PKI cryptographic signature checks prior to execution.

Step-by-Step Solution

1
Open Local Security Policy console by running 'secpol.msc' on the Windows 11 Professional workstation.
Access to Local Policies -> Security Options is established.
UAC security policies for domain-independent or standalone machines are managed within Security Options.
2
Locate 'User Account Control: Behavior of the elevation prompt for standard users' and select 'Automatically deny elevation requests'.
Standard users will receive an access denied message without any prompt to enter administrator credentials when trying to run elevated tasks.
Fulfills the requirement to prevent standard users from attempting privilege escalation or viewing credential prompts.
3
Locate 'User Account Control: Only elevate executables that are signed and validated' and set it to 'Enabled'.
Windows will enforce Public Key Infrastructure (PKI) signature validation on binary executables requesting administrative access before triggering elevation.
Fulfills the requirement to mandate digital signature verification for elevated software.

Key Concept

Local Security Policy UAC Security Options
Question 17Question

A systems administrator is configuring a reference workstation to create a golden master image that will be deployed to dozens of new computers across an enterprise network. Before capturing the OS image, the administrator needs to ensure that hardware-specific information and unique system identifiers are removed and that the image can be captured cleanly without file lock conflicts. Which of the following procedures should the administrator perform to achieve this? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Run the System Preparation tool (sysprep.exe) with the /generalize switch to remove computer-specific details like the Security Identifier (SID).; Boot the reference computer into Windows Preinstallation Environment (WinPE) to run the disk imaging capture utility.

Answer

To prepare and capture a golden master image for network deployment, the administrator must run `sysprep.exe /generalize` to strip unique system identifiers (SIDs) and boot into a WinPE environment to capture the offline system drive cleanly.
Executing the System Preparation tool (`sysprep.exe`) with the `/generalize` parameter removes system-unique information such as the computer security identifier (SID) and hardware profile details, allowing the OS image to be deployed across diverse hardware configurations. Booting into WinPE places the target system drive in an offline, unmounted state, allowing imaging tools to capture an exact image of the volume without file lock interference from active system processes.

Step-by-Step Solution

1
Generalize the operating system state
System-specific hardware drivers, SID, and unique identifiers are removed from the Windows installation.
Cloning an operating system without generalizing causes duplicate SIDs and configuration conflicts on the enterprise network.
2
Boot into Windows PE (WinPE)
The host OS volume is brought offline while running a minimal lightweight environment.
Running the image capture utility from WinPE avoids file locking and filesystem state changes that occur when imaging a live OS volume.

Key Concept

Windows OS Image Generalization and Capture Procedures
Estimated Time:1m 30s
Question 18Question

Following a component upgrade on a corporate desktop system, the machine powers on and system fans run at maximum speed, but the monitor displays no signal and the keyboard status lights remain unlit. No diagnostic beep codes are emitted from the motherboard speaker. Which of the following initial actions should the technician take to isolate this hardware failure? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Verify that the auxiliary 8-pin EPS12V CPU power connector is securely attached to the motherboard header; Reseat the memory modules and test system boot using a single module in the primary DIMM slot

Answer

The technician should verify that the auxiliary 8-pin EPS12V CPU power connector is securely connected and reseat the memory modules while testing with a single module in the primary DIMM slot.
When a computer powers on with fans running at high speed but shows no display, no POST beep codes, and unlit keyboard LEDs, the system is failing early in the power-on self-test (POST) process. The most common physical causes are missing CPU power (the auxiliary 8-pin EPS12V connector) or unseated/faulty memory modules. Checking the EPS12V power connection ensures the processor receives adequate voltage to execute BIOS instructions, and isolating/reseating RAM modules rules out memory initialization faults.

Step-by-Step Solution

1
Check motherboard auxiliary power connections
Ensures the CPU receives proper voltage for core execution and POST initiation
Without auxiliary CPU power (+12V EPS/ATX), the processor cannot execute BIOS/UEFI firmware code.
2
Isolate RAM modules by reseating and testing individually
Determines if an unseated module or faulty RAM stick is halting the POST sequence
Faulty or unseated RAM often prevents video display and system initialization while fans continue to run.

Key Concept

Pre-POST isolation of power delivery and RAM installation issues
Question 19Question

A field technician reports that a specialized telemetry logging app on a company-issued Android tablet takes a long time to start up, stutters when loading local data, and consumes excessive background memory. Other system utilities and mobile apps on the tablet perform normally. Which of the following initial, least-invasive troubleshooting steps should the technician take to resolve this issue? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Force stop the telemetry logging application and clear its application cache.; Check for and apply available software updates for the specific application.

Answer

The technician should force stop the application and clear its cache, as well as check for and apply available application updates.
In accordance with standardCompTIA least-invasive troubleshooting practices, isolated mobile application slowness and memory issues should be handled first by non-destructive measures such as force closing the app, clearing its temporary cache, and installing developer-provided app updates.

Step-by-Step Solution

1
Isolate the issue to the application layer
Confirm that only the telemetry logging application is experiencing slowness and background memory issues while the rest of the mobile OS operates normally.
Identifying that the problem is isolated to a single app prevents unnecessary system-wide troubleshooting or destructive OS actions.
2
Apply least-invasive application reset measures
Force stop the app process and clear its temporary cache files from settings.
Clearing temporary cache removes potentially corrupted temporary files and terminates hung execution threads without erasing user accounts or stored data.
3
Verify and apply application updates
Install any pending updates for the application.
Developers release software patches to fix memory leaks and performance glitches in mobile applications.

Key Concept

Least-invasive mobile application troubleshooting methodology
Question 20Question

While conducting a remote screen-sharing session to resolve a network printer installation issue, a Tier 1 support technician notices that the user has a spreadsheet displayed containing unencrypted Personal Identifiable Information (PII) of corporate clients. The user appears unaware of the visible data and is becoming impatient regarding the printer issue. Which of the following professional communication and compliance actions should the technician take in this scenario? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Respectfully inform the user of the visible sensitive data and ask them to close or minimize the document before proceeding with troubleshooting.; Maintain a professional, non-judgmental tone while clearly explaining the estimated time required to configure the printer driver.

Answer

The technician should politely notify the user to close or minimize the document containing sensitive client PII, and maintain a professional tone while clearly explaining expected timelines for the printer repair.
Professional support standards require technicians to protect customer privacy by requesting that sensitive PII be hidden prior to remote troubleshooting, while maintaining clear, jargon-free communication and setting proper timeline expectations.

Step-by-Step Solution

1
Address data privacy and confidentiality boundaries
The user secures the spreadsheet containing sensitive PII from view during the shared support session.
Technicians must respect confidentiality and handle PII appropriately by guiding the user to hide sensitive information rather than accessing or ignoring it.
2
Communicate status and maintain professional conduct
The user is informed of the repair process in clear language and understands expected wait times.
Setting realistic expectations and maintaining a calm, respectful demeanor prevents escalation when users are impatient.

Key Concept

Professional customer interaction, privacy compliance, active listening, and expectation setting during support sessions.
Page 1 / 40Next
All practice questions — CompTIA A+ (Core 1 & Core 2) | Examkin