Operational Procedures

390 questions

Question 1Question

Match each remote access technology or protocol on the left with its corresponding technical characteristic, default port configuration, and operational requirement on the right.

Click a left item, then click its matching right item

Items

Remote Desktop Protocol (RDP)
Microsoft Remote Assistance (MSRA)
Secure Shell (SSH)
Telnet
Virtual Network Computing (VNC)

Matches

Show answer & explanation

Answer

RDP matches TCP 3389 with host support limited to Windows Pro/Enterprise; MSRA matches TCP 3389 session sharing supported on Home and Pro editions; SSH matches encrypted CLI administration on TCP 22; Telnet matches unencrypted cleartext CLI management on TCP 23; VNC matches cross-platform RFB graphical control on TCP 5900.
Matching each technology correctly requires distinguishing between Windows OS edition constraints (RDP host vs MSRA), default port numbers (TCP 22, 23, 3389, 5900), and protocol security characteristics (SSH encrypted vs Telnet cleartext; RDP/MSRA native vs VNC RFB cross-platform).

Step-by-Step Solution

1
Analyze Windows graphical remote access protocols and edition constraints.
Differentiate RDP (discrete session, host requires Windows Pro/Enterprise/Education, TCP 3389) from MSRA (shared active session, invitation-based, works on Home editions, TCP 3389).
CompTIA exams strictly evaluate the host capability limitation of Windows Home edition regarding incoming RDP versus user-assisted MSRA.
2
Evaluate command-line interface (CLI) remote access protocols and security postures.
Identify SSH as the secure, encrypted terminal access protocol on TCP port 22, and Telnet as the legacy, unencrypted cleartext terminal protocol on TCP port 23.
Security best practices demand replacing unencrypted protocols like Telnet with encrypted alternatives like SSH.
3
Identify cross-platform graphical remote control standards.
Associate VNC with the Remote Frame Buffer (RFB) protocol and default listening port TCP 5900.
VNC is the standard open-source cross-platform tool for graphical desktop access across mixed operating system environments.

Key Concept

Remote Access Protocols, Default Listening Ports, Security Profiles, and Windows OS Edition Requirements
Question 2Question

An IT technician receives an urgent escalation from an executive manager who is unable to present at an upcoming board meeting because their laptop display is not showing on the conference room projector. The manager is visually stressed and expressing frustration about the technical failure. Which of the following is the most appropriate initial communication action for the technician to take?

Show answer & explanation

Answer: Actively listen while maintaining a calm, professional tone, acknowledge the urgency, and assure the manager that resolving the display issue is the immediate priority.

Answer

Actively listen while maintaining a calm, professional tone, acknowledge the urgency, and assure the manager that resolving the display issue is the immediate priority.
The correct response demonstrates proper interpersonal skills by maintaining a calm demeanor, actively listening to the user's concern, acknowledging the critical nature of the issue, and setting clear expectations without using confusing jargon or being dismissive.

Step-by-Step Solution

1
Assess the user's emotional state and professional context
Recognize that the executive is under high stress due to an imminent deadline.
Understanding the user's situation helps determine the appropriate tone and customer service response.
2
Apply de-escalation and active listening techniques
Maintain composure, avoid interrupting, and validate the urgency of the problem.
Calm and empathetic communication reassures the user that their problem is taking priority.
3
Set expectations and begin non-intrusive troubleshooting
Briefly state the immediate action steps in plain language before interacting with the system.
Keeping the user informed reduces anxiety and builds trust.

Key Concept

Professional customer communication, active listening, and stress de-escalation techniques during IT support calls.
Question 3Question

During a major IT infrastructure transition, a Tier 1 help desk technician receives an escalated user ticket regarding access failure to an encrypted network share containing time-sensitive financial records. Following initial troubleshooting, the technician determines that the issue stems from an unmapped Kerberos Service Principal Name (SPN) and missing Active Directory group delegation, which requires Tier 3 System Administration permissions to remediate. According to standard ticketing system lifecycle workflows, which of the following actions must the Tier 1 technician take before reassigning ownership of the ticket?

Show answer & explanation

Answer: Document all completed diagnostic steps, specific error codes, and the technical reason for escalation in the ticket work log, then reassign the ticket to the Tier 3 queue with an active in-progress status.

Answer

Document all completed diagnostic steps, specific error codes, and the technical reason for escalation in the ticket work log, then reassign the ticket to the Tier 3 queue with an active in-progress status.
The correct response highlights the fundamental ITSM requirement to thoroughly document all preliminary diagnostic actions, findings, error codes, and escalation justifications prior to transferring ticket ownership. Keeping the ticket active ensures that the ticket lifecycle continues seamlessly through Tier 3 without falsifying SLA metrics or losing incident history.

Step-by-Step Solution

1
Identify the scope of the technical issue and confirm that resolution exceeds Tier 1 scope/permissions.
Determined that Tier 3 intervention is necessary due to Kerberos SPN and Active Directory group administration requirements.
Technicians must recognize authorization boundaries and determine when escalation is required.
2
Record comprehensive internal work notes including diagnostic tests performed, error codes observed, and specific findings.
A clear audit trail of Tier 1 actions is attached directly to the existing incident record.
Thorough documentation prevents duplicate troubleshooting steps by Tier 3 personnel and speeds up time-to-resolution.
3
Update ticket routing attributes by assigning it to the appropriate specialized tier/queue while keeping the ticket state active (e.g., In Progress or Escalated).
Ownership transfers to Tier 3 without falsifying SLA resolution records or closing the issue prematurely.
Maintaining active lifecycle tracking ensures accurate incident management reporting and proper user communication.

Key Concept

Incident Escalation and Ticket Worklog Lifecycle Documentation
Question 4Question

While conducting a remote screen-sharing session to resolve a network printer installation issue, a Tier 1 support technician notices that the user has a spreadsheet displayed containing unencrypted Personal Identifiable Information (PII) of corporate clients. The user appears unaware of the visible data and is becoming impatient regarding the printer issue. Which of the following professional communication and compliance actions should the technician take in this scenario? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Respectfully inform the user of the visible sensitive data and ask them to close or minimize the document before proceeding with troubleshooting.; Maintain a professional, non-judgmental tone while clearly explaining the estimated time required to configure the printer driver.

Answer

The technician should politely notify the user to close or minimize the document containing sensitive client PII, and maintain a professional tone while clearly explaining expected timelines for the printer repair.
Professional support standards require technicians to protect customer privacy by requesting that sensitive PII be hidden prior to remote troubleshooting, while maintaining clear, jargon-free communication and setting proper timeline expectations.

Step-by-Step Solution

1
Address data privacy and confidentiality boundaries
The user secures the spreadsheet containing sensitive PII from view during the shared support session.
Technicians must respect confidentiality and handle PII appropriately by guiding the user to hide sensitive information rather than accessing or ignoring it.
2
Communicate status and maintain professional conduct
The user is informed of the repair process in clear language and understands expected wait times.
Setting realistic expectations and maintaining a calm, respectful demeanor prevents escalation when users are impatient.

Key Concept

Professional customer interaction, privacy compliance, active listening, and expectation setting during support sessions.
Question 5Question

A field technician is servicing hardware inside a server room. The technician disconnects a modular computer power supply unit (PSU) from the main AC electrical outlet and allows it to sit on an anti-static mat for 15 minutes. Intending to replace a faulty internal cooling fan inside the power supply casing, the technician attaches an ESD wrist strap to the PSU's metal enclosure and opens the PSU housing using insulated hand tools. Which of the following identifies the primary safety violation committed by the technician?

Show answer & explanation

Answer: Opening and attempting internal component repairs on a power supply unit rather than replacing the entire modular assembly

Answer

Opening and attempting internal component repairs on a power supply unit rather than replacing the entire modular assembly is the primary safety violation because power supplies contain high-voltage capacitors that retain lethal electrical charges even when unplugged.
Power supply units (PSUs) and CRT monitors contain high-voltage capacitors capable of storing lethal electrical charges long after being unplugged from an electrical outlet. According to CompTIA A+ safety standards, PSUs are considered non-field-serviceable components and should never be opened or repaired internally by a field technician. The entire PSU assembly must be replaced if faulty.

Step-by-Step Solution

1
Analyze the high-voltage hazard involved in opening a computer Power Supply Unit (PSU).
Recognize that PSUs store high voltage inside internal capacitive components.
Capacitors can retain lethal voltage levels for an extended period even after the unit is disconnected from external power.
2
Evaluate CompTIA safety procedures regarding field-serviceable parts.
Determine that PSUs are classified as non-field-serviceable assemblies.
Technicians must always replace the entire PSU assembly rather than disassembling the unit to fix internal components such as fans or capacitors.
3
Identify the primary safety violation from the scenario.
The act of opening the PSU casing poses a severe risk of electrical shock or electrocution.
Personal safety takes precedence over ESD precautions or tool selection when dealing with high-voltage hazards.

Key Concept

High-Voltage Safety and Non-Field-Serviceable Components
Question 6Question

An IT support technician is conducting an on-site troubleshooting session at a department manager's desk to resolve a recurring application error. While the technician is diagnosing the issue, the manager receives an urgent phone call and steps away from the desk without locking the workstation, leaving confidential employee performance evaluation documents open on the screen. The technician determines that resolving the software issue requires an immediate operating system reboot. Which of the following actions should the technician take next?

Show answer & explanation

Answer: Wait for the manager to return to the desk, explain the requirement for a system reboot, and allow the manager to save and close all sensitive files before proceeding.

Answer

The technician should wait for the manager to return, clearly communicate the necessity of a system reboot, and permit the manager to save and close confidential files prior to restarting.
CompTIA professional interaction guidelines specify that technicians must respect customer privacy and property at all times. When a system restart or disruptive action is required, the technician must communicate the necessity clearly to the user and allow the user to save and close any open or sensitive files themselves. Taking unilateral action on user files or initiating reboots while the user is away violates confidentiality, risks data loss, and compromises professional rapport.

Step-by-Step Solution

1
Assess the current state of the user's workspace and data sensitivity.
Identify that open, confidential files are present and a reboot is required.
Unscheduled restarts risk data loss, while interacting with confidential files without consent violates privacy guidelines.
2
Pause technical interventions while the user is away.
Avoid touching sensitive user documents or forcing a system shutdown.
Maintaining professional communication requires gaining explicit user consent before taking actions that affect user session state.
3
Communicate directly with the user upon their return.
Explain the technical rationale for the reboot and let the user handle their files.
Sets clear expectations and demonstrates respect for customer privacy and data ownership.

Key Concept

Respecting customer property, privacy, and securing user consent prior to destructive or disruptive system actions.
Question 7Question

An IT technician is reviewing a Python (.py) automation script deployed to process system log files across multiple workstations. The script reads a configuration threshold from an operating system environment variable to determine when to trigger log compression. The variable is retrieved into the script, but when the script compares this environment variable against an integer variable representing the current file size in megabytes (log_size_mb), the conditional statement raises a runtime TypeError exception and halts execution. Which of the following identifies the root cause of this failure and the correct solution?

Show answer & explanation

Answer: Environment variables are retrieved as string data types by default; the value must be explicitly cast to an integer before conducting a numeric comparison.

Answer

Environment variables are retrieved as string data types by default, requiring explicit casting to an integer using int() prior to numeric conditional evaluation.
In system scripting, environment variables stored by the operating system are treated strictly as string data types when imported into a script. In Python (.py), attempting to compare an integer variable with a string variable using relational operators (such as > or <) results in a runtime TypeError. The technician must explicitly convert (cast) the string retrieved from the environment variable into an integer using the int() function before evaluating the condition.

Step-by-Step Solution

1
Analyze the reported error type and script behavior.
A TypeError during relational comparison (<, >) indicates a data type mismatch between the two operands being evaluated.
Python does not automatically coerce string objects into integers during relational comparisons.
2
Identify the data type returned by environment variable constructs across scripting environments.
Operating system environment variables are stored and returned as string data types regardless of whether their contents represent numeric digits.
Scripting runtimes parse OS environment values as text strings by default.
3
Determine the necessary syntax construct to resolve the type mismatch.
Casting the environment variable using integer conversion syntax (e.g., int(os.environ['MAX_LOG_SIZE'])) aligns data types for valid comparison.
Explicit type casting allows numerical conditional constructs to execute properly without raising runtime exceptions.

Key Concept

Environment Variables and Data Type Casting in Scripting
Estimated Time:2m 0s
Question 8Question

A systems administrator is establishing remote access guidelines for an enterprise help desk. The organization's support policy establishes two specific operational requirements:

1. Help desk technicians must interactively co-browse and control an active user session on a Windows 11 workstation with the user's explicit permission, without logging out or locking the screen of the local user.
2. Server administrators must establish encrypted command-line administrative sessions to manage remote Linux servers over the network.

Which combination of remote access technologies and standard port assignments fulfills both operational requirements?

Show answer & explanation

Answer: Microsoft Remote Assistance (MSRA) utilizing TCP port 3389, and Secure Shell (SSH) utilizing TCP port 22.

Answer

Microsoft Remote Assistance (MSRA) utilizing TCP port 3389, and Secure Shell (SSH) utilizing TCP port 22.
Microsoft Remote Assistance (MSRA) uses TCP port 3389 to allow a help desk technician to connect to a user's machine via invitation, enabling both parties to view and control the desktop simultaneously without locking the user out. Secure Shell (SSH) operates on TCP port 22 to establish an encrypted shell session for managing Linux systems.

Step-by-Step Solution

1
Analyze Requirement 1 for user assistance session behavior.
Microsoft Remote Assistance (MSRA) or Quick Assist is required because client Windows operating systems terminate or lock out the active local session when an inbound Remote Desktop Protocol (RDP) session connects. MSRA allows shared interactive control on TCP port 3389.
RDP enforces single-session limits on client editions of Windows, whereas MSRA explicitly supports invitation-based co-browsing.
2
Analyze Requirement 2 for secure command-line administration.
Secure Shell (SSH) operating on default TCP port 22 provides encrypted terminal access for remote Linux server management.
Telnet operates on TCP port 23 without encryption, failing the mandate for secure transmission.
3
Combine the compliant technologies and standard ports.
The correct combination is MSRA (TCP 3389) for interactive user assistance and SSH (TCP 22) for encrypted CLI management.
This combination satisfies both session preservation and encryption constraints.

Key Concept

Distinguishing interactive session behavior (MSRA vs RDP) and remote protocol encryption requirements (SSH vs Telnet).
Estimated Time:1m 30s
Question 9Question

During an internal investigation into suspicious data transfers, an IT support specialist is sent to secure a compromised workstation in an empty office suite. The specialist disconnects the workstation's network cable, powers down the system, attaches an evidence label with the serial number, and seals the unit in a container. However, before handing the equipment over to the legal forensics team the next morning, the specialist leaves the sealed container in an unlocked office cubicle overnight without logging storage location updates or transfer signatures. Which of the following best explains why this evidence may be rendered legally inadmissible?

Show answer & explanation

Answer: The specialist failed to maintain an unbroken record of physical custody and secure storage control overnight.

Answer

The specialist failed to maintain an unbroken record of physical custody and secure storage control overnight.
Chain of custody protocols require a continuous, verifiable, and documented record of evidence possession and secure storage from seizure until court presentation. Leaving the evidence overnight in an unlocked cubicle creates a gap in physical control and documentation, allowing opposing counsel to argue that evidence could have been tampered with or altered.

Step-by-Step Solution

1
Analyze the incident responder's actions regarding evidence preservation.
The specialist properly isolated the network cable and labeled/sealed the hardware, but left the item in an unlocked cubicle overnight without logging.
Chain of custody requires documenting every individual who handled the evidence, the exact timestamps of transfers, and continuous verification of secure storage.
2
Identify the procedural flaw in evidence handling.
Leaving evidence in an unmonitored, unlocked area overnight introduces a break in custody and control.
An unmonitored storage period allows for potential unauthorized access or tampering, making it impossible to guarantee evidence integrity in court.
3
Select the option that correctly describes the legal consequence of this procedural gap.
Failing to document secure storage and maintain unbroken physical control invalidates the chain of custody record.
Evidence admissibility relies strictly on proving an unbroken chain of custody from initial seizure to courtroom presentation.

Key Concept

Chain of Custody and Evidence Handling
Estimated Time:2m 0s
Question 10Question

An IT technician detects suspicious network traffic originating from a workstation on the corporate network. Arrange the basic incident response steps in the correct chronological order from first to last according to standard CompTIA procedures.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct order of incident response steps is: 1. Identify and confirm the security incident, 2. Report the incident to the designated security team or management, 3. Isolate the affected workstation from the network, and 4. Preserve evidence and document the chain of custody.
According to standard CompTIA incident response guidelines, a first responder must first identify that an incident is taking place. Once identified, the technician reports the incident to appropriate supervisors or incident response management. Next, the affected system is isolated from the network to prevent further damage or data exfiltration. Finally, evidence preservation and chain of custody documentation are performed to maintain legal integrity.

Step-by-Step Solution

1
Identify the incident
The initial security anomaly is detected and verified.
Incident response begins by identifying an event as a security incident.
2
Report the incident
Security personnel and management are informed.
Reporting ensures proper authorization and escalation protocols are followed.
3
Isolate the system
The device is disconnected from network communication.
Isolation contains the incident and prevents lateral movement of threats.
4
Preserve evidence and log custody
Digital evidence is secured and logged for forensic analysis.
Preservation must occur in a controlled manner after the system is contained.

Key Concept

Standard First Responder Incident Response Lifecycle
Question 11Question

A network administrator is configuring remote administration for a newly deployed Linux server that must be managed via command line across an untrusted public network. A technician proposes enabling Telnet to allow remote console access, noting that Telnet traffic on its standard port is already open on the firewall. Why is this proposal insecure, and which technology and default port should be implemented instead according to security best practices?

Show answer & explanation

Answer: Telnet transmits credentials and session data in unencrypted cleartext; Secure Shell (SSH) operating over TCP port 22 should be configured instead.

Answer

Telnet transmits credentials and session data in unencrypted cleartext; Secure Shell (SSH) operating over TCP port 22 should be configured instead.
Telnet lacks encryption, transmitting all authentication credentials and session commands in cleartext over TCP port 23. To secure command-line administration across untrusted networks, SSH must be used because it encrypts the entire connection using TCP port 22.

Step-by-Step Solution

1
Analyze the security requirements for remote administration.
Management occurs across an untrusted network and requires command-line console access.
Cleartext protocols expose sensitive administrative credentials to eavesdropping.
2
Evaluate the proposed protocol (Telnet).
Telnet operates on TCP port 23 without encryption, making it unsuited for secure remote access.
All traffic sent via Telnet can be captured and read in cleartext by malicious actors.
3
Identify the secure alternative and its default port.
SSH provides encrypted shell access over TCP port 22.
SSH encrypts authentication and command execution, fulfilling security and operational requirements.

Key Concept

Remote management protocols and default port security (Telnet TCP 23 vs SSH TCP 22)
Estimated Time:1m 15s
Question 12Question

An IT administrator for a regional healthcare provider is configuring an endpoint ticketing and logging application. During a routine audit of system logs, the administrator discovers that support technicians have been entering patient health insurance policy numbers, clinical diagnosis codes, and treatment notes into an unencrypted free-text field. This log data is automatically synchronized to an unencrypted cloud storage repository. Which of the following regulatory compliance frameworks is directly violated by exposing this specific category of data?

Show answer & explanation

Answer: HIPAA, because health insurance details and clinical diagnosis codes are classified as Protected Health Information (PHI).

Answer

HIPAA, because health insurance details and clinical diagnosis codes are classified as Protected Health Information (PHI).
The correct response identifies HIPAA because health insurance policy numbers, clinical treatment notes, and medical diagnosis codes constitute Protected Health Information (PHI). Under the HIPAA Privacy and Security Rules, covered entities must implement strict safeguards—such as encryption at rest and in transit—to protect PHI from unauthorized disclosure.

Step-by-Step Solution

1
Analyze the data types described in the scenario.
The data consists of patient health insurance policy numbers, clinical diagnosis codes, and treatment notes.
Identifying the specific category of data is essential for determining which privacy regulation applies.
2
Classify the data category under regulatory standards.
Individually identifiable health data created, used, or maintained by a healthcare provider is classified as Protected Health Information (PHI).
PHI encompasses health status, provision of healthcare, and payment for healthcare linked to an individual.
3
Map the data classification to the corresponding regulatory mandate.
The Health Insurance Portability and Accountability Act (HIPAA) mandates technical, physical, and administrative safeguards (including encryption) to protect PHI.
Storing unencrypted PHI in a public cloud repository directly violates HIPAA Security and Privacy Rules.

Key Concept

Protected Health Information (PHI) under HIPAA Compliance
Estimated Time:2m 0s
Question 13Question

An IT technician is inspecting an enterprise uninterruptible power supply (UPS) unit located in a remote equipment closet. The technician notices that several large sealed lead-acid (SLA) batteries within the enclosure are swollen, emitting a sharp sulfur-like odor, and showing signs of chemical corrosion around the terminal posts. Prior to attempting any handling, containment, or removal of the damaged components, which of the following actions should the technician take FIRST?

Show answer & explanation

Answer: Consult the Safety Data Sheet (SDS) for lead-acid batteries to determine specific chemical handling protocols and required personal protective equipment.

Answer

Consult the Safety Data Sheet (SDS) for lead-acid batteries to determine specific chemical handling protocols and required personal protective equipment.
When dealing with damaged chemical power sources such as leaking or swollen sealed lead-acid (SLA) batteries, the technician's immediate priority is safety compliance. Consulting the Safety Data Sheet (SDS) provides essential information regarding necessary Personal Protective Equipment (PPE), first-aid measures, spill neutralization procedures, and regulatory disposal mandates.

Step-by-Step Solution

1
Identify the primary hazard present in the scenario.
Recognize that swollen, leaking sealed lead-acid (SLA) batteries present immediate chemical (sulfuric acid) and thermal/electrical hazards.
Before performing physical labor on hazardous items, safety compliance requires reviewing documentation specific to the chemical composition.
2
Select the proper initial safety procedure.
Refer to the Safety Data Sheet (SDS) to ascertain proper Personal Protective Equipment (PPE) such as face shields, apron, and acid-resistant gloves, as well as spill containment guidelines.
CompTIA standards state that SDS consultation is the mandatory first step when encountering chemical spills or compromised hazardous substances.
3
Evaluate why alternative actions are unsafe or non-compliant.
Discard ESD wrist strap usage (shock/short hazard), alcohol wiping (flammability/ineffectiveness), and standard e-waste disposal (environmental regulation violation).
Ensures full compliance with occupational safety and environmental protection laws.

Key Concept

Safety Data Sheet (SDS) Compliance and Hazardous Chemical/Battery Safety
Question 14Question

A field technician is assigned to clean heavy industrial dust and particulate buildup from the internal components of a server node deployed in a harsh manufacturing facility. To adhere to CompTIA safety standards regarding personal protection, static control, and hardware preservation, in what sequential order should the technician perform the steps for this maintenance procedure?

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct procedural sequence is: 1) Disconnect all power sources and transport the unit to a well-ventilated area while wearing PPE; 2) Connect the server chassis to an ESD grounding system; 3) Immobilize the internal cooling fan blades to prevent back-EMF generation; 4) Displace dust using a specialized ESD-safe vacuum or grounded compressed air unit; 5) Wipe down external surfaces with a lint-free cloth and inspect filters before re-installation.
The correct sequence prioritizes technician safety and power isolation first (disconnecting power, using PPE, and working in a ventilated area). Next, static safety is established by bonding the chassis to ground. Third, internal mechanical components (fans) are secured to prevent electrical generation from back-EMF. Fourth, specialized ESD-safe tools clear internal debris. Finally, surface finishing and filter inspection take place before restoring power.

Step-by-Step Solution

1
Ensure physical safety, power isolation, and proper ventilation with PPE.
The server is de-energized, isolated from live power, and moved to an area where airborne dust won't contaminate office or server room air or harm the technician.
Personal safety (respirator/goggles) and environmental containment are the primary concerns prior to disturbing heavy particulate.
2
Establish ESD grounding controls.
The equipment chassis and technician are at the same ground potential, preventing static discharge damage to sensitive silicon chips.
Air movement across dry surfaces generates substantial triboelectric static charges, making grounding essential before using air tools.
3
Secure fan impellers against free rotation.
Cooling fan motors cannot act as electrical generators when high-velocity air hits them.
Forced air spinning unsecured fan blades turns the DC fan motor into a generator, sending destructive back-EMF voltage into delicate motherboard circuits.
4
Remove internal dust using specialized ESD-safe equipment.
Particulate matter is removed without static accumulation or component damage.
Standard household vacuums accumulate massive static charges on plastic nozzles; specialized ESD vacuums or grounded air tools are mandatory.
5
Perform final cleanup, surface wipe down, and pre-deployment inspection.
Residual dust is cleaned, intake filters are verified, and the system is safely prepared to return to operational service.
Final physical verification ensures no loose debris or blocked air paths remain before re-applying power.

Key Concept

Environmental Controls and ESD Safety Procedures for System Maintenance
Question 15Question

A help desk technician receives a call from an employee who is frustrated because a recent mandatory software update altered their familiar file-saving interface. The employee insists that the technician revert the update for their workstation immediately, stating that it hinders their daily productivity. Which of the following is the most professional communication response for the technician to take?

Show answer & explanation

Answer: Listen attentively to the user's concerns without interrupting, validate their frustration, and clearly explain what support can provide while offering guidance on navigating the new interface.

Answer

The technician should listen attentively to the user's concerns without interrupting, validate their frustration, and clearly explain what support can provide while offering guidance on navigating the new interface.
The correct response demonstrates professional communication by practicing active listening, de-escalating customer frustration with empathy, avoiding technical jargon, and setting realistic expectations while assisting the user.

Step-by-Step Solution

1
Practice active listening and maintain professional composure
The technician allows the user to vent their frustration fully without interruption or defensiveness.
De-escalating customer frustration requires acknowledging their feelings and showing empathy.
2
Set expectations and offer constructive assistance
The technician explains boundaries regarding mandatory updates clearly while providing guidance on adapting to the new interface.
Clear communication helps set realistic expectations while demonstrating support and willingness to help.

Key Concept

Professional Communication, Active Listening, and De-escalation Techniques
Question 16Question

A systems administrator is planning to upgrade the primary directory service schema for a corporate network. To ensure compliance with standard IT operational procedures, place the following change management phases in the correct chronological order from first to last.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct chronological sequence is: first, define the purpose and scope of the proposed modification; second, perform a risk assessment and construct a detailed backout plan; third, submit the change proposal to the Change Advisory Board (CAB) for formal approval; and finally, notify impacted users and implement the modification during an approved maintenance window.
The standard CompTIA change management workflow follows a specific logical lifecycle: identifying the purpose and scope of the change comes first, followed by analyzing business risks and drafting a comprehensive backout plan. Once the change package is prepared, it is submitted to the Change Advisory Board (CAB) for formal review and authorization. Finally, after approval is granted, affected stakeholders are notified and the change is deployed within a scheduled maintenance window.

Step-by-Step Solution

1
Identify the initial planning phase
Define the purpose and scope of the proposed change
Before any operational changes are submitted or analyzed, the administrator must clearly document what is being changed and the rationale behind it.
2
Identify risk assessment and mitigation planning
Perform a risk assessment and construct a detailed backout plan
Understanding potential impacts and creating a rollback procedure are mandatory prerequisite elements of a formal change request.
3
Identify the approval authority milestone
Submit the change proposal to the Change Advisory Board (CAB) for formal approval
The CAB reviews the completed change request, risk assessment, and backout plan before granting authorization to proceed.
4
Identify the execution and communication phase
Notify impacted users and implement the modification during an approved maintenance window
Execution and user notification take place only after authorization has been granted by the governing body.

Key Concept

Standard Change Management Process Lifecycle
Question 17Question

A support technician finishes resolving an issue where a remote employee's workstation was unable to synchronize local database files with the corporate repository following a network disruption. The technician successfully restored the database synchronization service and verified data integrity. According to standard operating procedures for ticketing system workflows, which of the following actions should the technician perform before resolving and closing the incident ticket? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: Document the detailed root cause, diagnostic findings, and specific resolution steps in the ticket work log.; Obtain explicit confirmation from the end user that the file synchronization functionality is fully restored.

Answer

The technician must document the detailed root cause, diagnostic findings, and specific resolution steps in the ticket work log, and obtain explicit confirmation from the end user that the file synchronization functionality is fully restored.
Standard ticketing system workflows dictate that once an incident is technically remediated, the technician must document all work performed, including root cause and resolution steps, into the work log for knowledge management. Furthermore, the technician must verify with the end user that the system is functioning to their satisfaction before updating the ticket status to resolved or closed.

Step-by-Step Solution

1
Identify mandatory steps for ticket resolution and closure.
Recognize that complete technical logging and customer verification are essential elements of the incident lifecycle.
Standard Help Desk SLA protocols require both structured documentation and user acceptance before marked resolved.
2
Evaluate ticket closure tasks against standard operating procedures.
Select work log documentation and end-user verification as mandatory final steps.
Accurate documentation aids knowledge sharing across support tiers, while user confirmation prevents premature issue closure.

Key Concept

Incident Ticket Documentation and User Verification Workflow
Estimated Time:1m 30s
Question 18Question

A senior infrastructure administrator is planning a major upgrade to an enterprise directory service schema across an organization's domain controllers. Place the standard change management phases in the correct chronological order from first step to final step.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The proper change management sequence begins by defining the purpose and scope, followed by performing a risk assessment and documenting a backout plan, then obtaining Change Advisory Board (CAB) approval, and finally notifying end users while scheduling the maintenance window.
In standard ITIL and CompTIA change management workflows, the initial step is defining the purpose and scope of the proposed change. Next, engineers evaluate potential risks and construct a comprehensive backout plan. Once these prerequisites are met, the request is submitted to the Change Advisory Board (CAB) for formal review. Upon receiving CAB approval, administrators notify affected end users and schedule the implementation within an authorized maintenance window.

Step-by-Step Solution

1
Define purpose and scope
The exact baseline requirements and boundaries of the change are documented.
Every change request must start with a clear objective and defined scope before further planning can occur.
2
Perform risk assessment and prepare backout plan
Impact analysis is completed and a detailed rollback procedure is established.
Understanding potential failure modes and having a backout plan is mandatory for approval consideration.
3
Submit for Change Advisory Board (CAB) authorization
Formal review and approval from key stakeholders are obtained.
CAB oversight ensures that business risk and schedule conflicts are fully addressed prior to implementation.
4
Notify end users and schedule maintenance window
Stakeholders are informed and execution timing is established.
User notification and downtime scheduling must only take place after formal change approval has been granted.

Key Concept

Change Management Process Lifecycle
Question 19Question

A network engineer is preparing a change request to modify core routing table entries across several regional branch offices. The engineer has defined the business purpose, documented the precise scope, performed a thorough risk assessment, and scheduled the change during a standard maintenance window. During review, the Change Advisory Board (CAB) rejects the submission as incomplete. Which of the following critical change management elements was most likely missing from the engineer's submission?

Show answer & explanation

Answer: A documented rollback plan outlining specific recovery steps if network connectivity fails during deployment

Answer

A documented rollback plan outlining specific recovery steps if network connectivity fails during deployment
Formal change management procedures require a documented rollback (backout) plan to be included in the change request prior to submission to the Change Advisory Board (CAB). The rollback plan ensures that technicians can quickly restore systems to their previous working state if the implemented change causes unanticipated network outages or instability.

Step-by-Step Solution

1
Analyze the change request components provided in the scenario.
The engineer included the purpose, scope, risk assessment, and proposed deployment schedule.
CompTIA change management processes require specific core components before CAB approval can be granted.
2
Identify missing mandatory change request components.
The submission lacked a rollback (backout) plan, end-user notification strategy, or pre-testing plan.
Without a rollback plan, the organization risks prolonged downtime if the configuration change introduces unexpected routing loops or site outages.
3
Evaluate the choices to select the missing requirement.
The option specifying a documented rollback plan identifies the necessary pre-approval document required by the CAB.
CAB approval depends on risk mitigation strategies, including an explicit step-by-step backout procedure.

Key Concept

Change Management Processes - Required Components for Change Request
Question 20Question

A technician is trying to configure incoming Remote Desktop access on a user's workstation running Windows 11 Home. However, the setting to enable incoming Remote Desktop connections is not available in System Settings. Which of the following best explains why the technician cannot enable this feature?

Show answer & explanation

Answer: Windows Home edition can initiate outgoing Remote Desktop sessions but cannot act as a Remote Desktop host for incoming connections.

Answer

Windows Home edition supports outgoing Remote Desktop client connections, but lacks the ability to host incoming Remote Desktop sessions.
Microsoft Windows Home editions include the RDP client software, allowing users to connect out to other remote systems. However, incoming Remote Desktop host capability is explicitly restricted to Windows Pro, Enterprise, and Education editions. To allow incoming RDP sessions, the operating system must be upgraded.

Step-by-Step Solution

1
Identify the OS edition and remote feature requirement
The target workstation is running Windows 11 Home edition, and the goal is to host an incoming RDP session.
Microsoft restricts certain enterprise and management features by operating system edition.
2
Evaluate feature availability across Windows editions
Windows Home edition includes the Remote Desktop Connection client (RDP client) to connect to remote computers, but does not support acting as an RDP server/host.
Hosting incoming Remote Desktop sessions requires Windows Pro, Enterprise, or Education edition.

Key Concept

Windows Edition Remote Desktop Host Limitations
Page 1 / 20Next