Tüm alıştırma soruları

423 soru

Soru 181Soru

An IT security technician is decommissioning a magnetic Hard Disk Drive (HDD) that stored highly sensitive enterprise financial data. To maintain compliance and follow industry best practices, the technician must execute a complete sanitization, destruction, and chain-of-custody lifecycle protocol. What is the correct sequence of steps the technician should take from initial decommissioning to final verification?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The proper sequence begins with establishing chain-of-custody documentation, followed by logical purging (ATA Secure Erase), physical demagnetization (degaussing), mechanical destruction (shredding), and concluding with obtaining a Certificate of Destruction.
The complete asset disposal lifecycle requires establishing chain of custody first to track media accountability, followed by logical purging (ATA Secure Erase) to protect data in transit. Magnetic sanitization (degaussing) and physical destruction (shredding) ensure irreversible destruction. Finally, auditing and archiving a formal Certificate of Destruction closes the compliance loop.

Adım Adım Çözüm

1
Establish initial accountability and tracking.
Drive serial number is logged into the chain-of-custody tracking software.
Tracking prevents unauthorized movement or loss of sensitive media prior to sanitization.
2
Execute logical data sanitization.
Drive data is purged using an ATA Secure Erase operation while still attached to storage hardware.
Purging media prior to physical removal mitigates risk if media is intercepted before physical destruction.
3
Apply magnetic sanitization.
Drive platters are exposed to a degausser, rendering magnetic tracks unreadable and drive electronics non-functional.
Degaussing destroys magnetic domains on spinning platters, preventing data recovery.
4
Perform physical destruction.
The degaussed drive is physically shredded into small fragments.
Physical destruction guarantees complete physical impossibility of media reconstruction.
5
Finalize compliance and auditing logs.
A Certificate of Destruction is received, verified against serial numbers, and archived.
Provides legal and regulatory proof that sensitive data was handled according to compliance standards.

Anahtar Kavram

Chain of Custody and Secure Data Disposition Lifecycle for Magnetic Media
Soru 182Soru

A technician is troubleshooting a desktop computer that powers on when the power button is pressed, but it fails to complete the Power-On Self-Test (POST) and continuously emits repeating single beep codes. Which sequence of steps should the technician follow to systematically isolate and resolve the memory issue?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The proper troubleshooting sequence requires isolating the system to core components, inspecting cleared memory slots, verifying motherboard functionality using a single known-good memory module, and systematically testing individual original RAM sticks.
According to CompTIA hardware troubleshooting methodology, isolating a memory POST issue requires minimizing system complexity first, inspecting physical slots, confirming system stability with a single known-good RAM module, and then testing suspect modules individually.

Adım Adım Çözüm

1
Isolate system hardware
Peripheral interference and expansion card conflicts are eliminated.
Before testing memory specifically, non-essential hardware must be removed to avoid false diagnostics.
2
Clear and inspect DIMM slots
Slots are verified clean and ready for single-channel testing.
Removing all RAM modules clears potential channel seating errors.
3
Establish a working baseline with known-good RAM
System completes POST or confirms slot integrity.
Using a known-good module verifies whether the motherboard memory bus and controller are functional.
4
Isolate defective RAM stick
The faulty RAM module is identified for replacement.
Testing original modules individually isolates the specific stick causing continuous POST beep codes.

Anahtar Kavram

RAM POST Failure Diagnostic Sequencing

Alternatif Yöntem

Consulting motherboard diagnostic LEDs or a POST card display can provide immediate status codes before pulling RAM sticks.
Tahmini Süre:1m 30s
Soru 183Soru

A Windows workstation application has stopped responding, causing localized performance degradation. Place the standard troubleshooting steps in the correct sequence to inspect and resolve this application failure.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence is: first, press Ctrl + Shift + Esc to open Task Manager; second, locate the hung application in the Processes tab to verify high resource utilization; third, select the non-responsive application process and click End Task; fourth, open Event Viewer and navigate to the Application log to inspect crash details.
The proper troubleshooting flow requires immediate action to restore system usability before performing deep log analysis. Launching Task Manager with Ctrl + Shift + Esc provides immediate access to active processes. Identifying the frozen process on the Processes tab allows the technician to target the correct application. Executing End Task releases stuck system resources. Finally, checking the Application log in Event Viewer provides diagnostic event details for post-incident root cause analysis.

Adım Adım Çözüm

1
Launch Task Manager using the keyboard shortcut Ctrl + Shift + Esc.
Task Manager opens, displaying real-time system performance and active process lists.
You must open Task Manager before you can inspect or manage running processes.
2
Examine the Processes tab to locate the frozen or high-utilization application.
The target process status shows '(Not Responding)' or excessive resource usage.
Identifying the specific process ensures the correct application is targeted.
3
Select the application and click End Task.
The unresponsive process terminates and system responsiveness is restored.
Ending the hung task frees trapped memory and CPU cycles.
4
Open Event Viewer and check the Windows Application log for faulting module entries.
Technician gathers Event IDs and error codes for long-term remediation.
Post-incident diagnostic log review identifies root causes without keeping the system frozen.

Anahtar Kavram

Troubleshooting Unresponsive Applications and Resource Isolation Sequence
Soru 184Soru

A remote IT support technician receives a call from a distressed customer whose system crashed during a high-priority business transaction. The customer is frustrated, speaking rapidly, and demanding an immediate fix. Place the following professional communication and user interaction steps in the correct chronological sequence from initial call handling to final call closure.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct chronological sequence is: (1) Actively listen and de-escalate, (2) Set expectations and request remote control permission, (3) Instruct user to close confidential/PII data, (4) Perform troubleshooting with clear non-technical explanations, and (5) Verify resolution with user and document the ticket.
The correct workflow follows standard CompTIA operational procedures for user interaction: first de-escalate and listen to establish communication; next request remote permission and set time expectations; third protect confidentiality by having the user clear PII; fourth conduct troubleshooting using clear, jargon-free explanations; and finally verify problem resolution with the user and complete formal ticket documentation.

Adım Adım Çözüm

1
Initial Customer Engagement & De-escalation
Customer feels heard and de-escalated; full problem context is gathered without interruption.
Active listening and maintaining a professional tone are required first when dealing with frustrated users.
2
Establishing Scope & Permission
User understands expected timelines and gives consent for remote access.
Proper protocol requires setting expectations and getting customer permission before taking control of their system.
3
Protecting Privacy and Confidential Information
Screen visual field is cleared of confidential and sensitive personal data.
CompTIA best practices dictate safeguarding customer privacy and PII before viewing remote screens.
4
Technical Execution with Clear Communication
Issue is resolved without confusing the customer with acronyms or technical jargon.
Keeping the customer informed using plain language builds confidence and avoids miscommunication.
5
Verification and Documentation
Issue fix is confirmed by user, customer sign-off is achieved, and incident details are recorded.
A ticket should only be closed after user verification, proper documentation, and formal customer confirmation.

Anahtar Kavram

Best practices for professional communication, customer de-escalation, privacy preservation, and remote support workflows.
Soru 185Soru

An IT technician is preparing to harden a newly installed Windows workstation before introducing it into an enterprise environment. Place the following workstation hardening steps in the correct standard procedural sequence, from first to last.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence for workstation hardening is: 1) Change default credentials and disable unused default accounts, 2) Apply all operating system updates and security patches, 3) Disable unnecessary system services and AutoPlay/AutoRun features, and 4) Enable host-based firewall rules and anti-malware protection.
A baseline workstation hardening workflow follows a logical order: first secure user accounts and default credentials to prevent basic unauthorized access; second, apply system updates and patches to address known security flaws; third, decrease the attack surface by disabling unneeded services and automatic feature execution; and finally, enable host firewalls and anti-malware software for continuous active defense.

Adım Adım Çözüm

1
Secure account access
Default credentials are changed and unneeded built-in accounts are disabled.
Prevents unauthorized access using widely known factory default accounts.
2
Patch software vulnerabilities
The operating system is fully updated with security hotfixes.
Closes known system vulnerabilities so update routines work reliably before services are restricted.
3
Reduce system attack surface
Unused services and features like AutoPlay are turned off.
Eliminates superfluous entry points that attackers or automated scripts could exploit.
4
Deploy active defensive security controls
Host firewall rules and anti-malware defenses are active.
Establishes real-time filtering and scanning for ongoing workstation operation.

Anahtar Kavram

Standard Workstation Hardening Procedure
Soru 186Soru

An IT support technician is following standard operational procedures to manage a reported end-user service request. Place the standard service desk ticketing lifecycle steps in the correct chronological order from first to last.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence for the IT service desk ticketing lifecycle is: 1) Identify user issue and create ticket, 2) Perform initial investigation and Tier 1 diagnostics, 3) Escalate ticket with notes, 4) Implement resolution and verify functionality with user, 5) Log root cause details and close ticket.
The correct order follows the standard IT service management lifecycle: incident intake/creation, initial triage/diagnostics, escalation (if required), resolution implementation with user verification, and final ticket closure with complete root cause documentation.

Adım Adım Çözüm

1
Begin by logging the incident upon receipt of the request.
The ticket is assigned a unique identifier, category, and initial priority level.
Accurate logging ensures proper routing and tracking within the ticketing system.
2
Triage the incident using standard diagnostic workflows.
Basic causes are ruled out, and initial findings are documented.
Tier 1 triage attempts to resolve simple issues quickly before unnecessary escalation.
3
Escalate complex technical issues that require specialized skills.
Ownership transfers to Tier 2 support alongside full case history.
Including diagnostic context prevents duplicate efforts by higher-level technicians.
4
Apply the fix and verify that normal operations are restored.
The user confirms the problem is resolved and system functionality is verified.
Verification ensures the solution solved the issue without introducing collateral problems.
5
Record comprehensive resolution documentation and close the record.
The ticket transitions to closed status.
Detailed resolution logs populate knowledge bases and satisfy compliance auditing.

Anahtar Kavram

Standard Ticketing System Lifecycle Workflows
Soru 187Soru

A systems technician is tasked with re-hardening a company laptop that was recently returned from a high-risk remote assignment before allowing it back onto the internal corporate network. Arrange the following workstation hardening and remediation steps in the correct procedural sequence from first to last.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence for re-hardening the remote workstation is: 1) Disconnect all physical and wireless network interfaces to isolate the device, 2) Boot the system using a trusted external rescue disk to perform an offline malware scan, 3) Disable the built-in Guest account and unbind non-essential network protocol bindings and services, 4) Configure Local Security Policy to enforce password-protected screen saver locks and disable AutoPlay/AutoRun, and 5) Connect the workstation to a restricted remediation VLAN to apply system updates and patch definitions.
Hardening a returning untrusted endpoint must always follow a defense-in-depth sequence: Isolation → Verification/Cleaning → OS Baseline Reduction → Policy Enforcement → Segregated Updating. Isolating network access first prevents threat proliferation. Offline scanning verifies system integrity. Disabling unused accounts and services reduces attack surface. Enforcing Local Security Policy ensures endpoint operational security, and using a segregated remediation VLAN allows patching without exposing production assets.

Adım Adım Çözüm

1
Isolate the endpoint
Network communication is completely severed.
Prevents command-and-control communication or lateral movement of potential malware while the device is in an unverified security state.
2
Perform offline security verification
Malware scan completes without OS-level interference.
Scanning offline guarantees that malicious kernel drivers or rootkits are inactive and detectable.
3
Apply attack surface reduction baselines
Unused services, protocols, and default accounts are disabled.
Eliminating unnecessary services minimizes potential vectors for unauthorized local or remote access.
4
Enforce endpoint compliance policies
Screensaver locks and AutoPlay restrictions are active.
Configuring Local Security Policy hardens the OS against physical tampering and unauthorized removable media execution.
5
Patch and update in a controlled environment
OS patches and antivirus signatures are fully updated.
Using a isolated remediation VLAN ensures updates are retrieved safely before the endpoint is granted production network access.

Anahtar Kavram

Workstation Hardening and Incident Remediation Lifecycle
Soru 188Soru

An IT technician is preparing to decommission several enterprise magnetic hard disk drives (HDDs) containing sensitive personnel records. To adhere to organizational security policies and maintain regulatory compliance, the disposal process must follow strict data sanitization and chain-of-custody procedures. In what sequence should the technician perform the following decommissioning steps?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence begins with logging the drive serial numbers for chain-of-custody tracking, followed by performing a logical sanitization pass, executing physical destruction or degaussing, and finally obtaining and archiving a Certificate of Destruction.
Proper media disposal mandates initializing chain-of-custody documentation first by logging serial numbers. Next, logical sanitization (overwriting) is performed while drives are operational. Physical destruction (degaussing or shredding) permanently renders media unreadable, and finally, obtaining a Certificate of Destruction completes compliance recording.

Adım Adım Çözüm

1
Establish chain-of-custody logging
Drive serial numbers and asset tags are logged into inventory tracking.
Tracking must begin prior to handling or transport to establish legal accountability for sensitive media.
2
Perform logical drive sanitization (purge)
All data sectors on the HDDs are overwritten.
Sanitizing data logically protects confidential records while the drive is intact before physical transport or destruction.
3
Execute physical media destruction
The drives are degaussed or physically shredded.
Degaussing neutralizes magnetic domains and shredding physically breaks platters, ensuring recovery is impossible.
4
Archive compliance documentation
A formal Certificate of Destruction is archived.
Final documentation validates to auditors that data destruction met mandatory regulatory standards.

Anahtar Kavram

Lifecycle and Chain of Custody for Hard Drive Disposition
Soru 189Soru

A technician is troubleshooting a Windows workstation experiencing system instability due to corrupted system files. Diagnostic logs indicate that the underlying component store itself may also be corrupted. In what order should the technician perform the following operational steps to diagnose, repair the component store, restore corrupted system files, and complete the remediation process?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct order is: 1) Run dism /online /cleanup-image /scanhealth to check component store health, 2) Run dism /online /cleanup-image /restorehealth to repair the component store, 3) Run sfc /scannow to repair protected system files, and 4) Reboot the workstation to apply pending file changes.
When both the Windows component store and core system files are corrupted, DISM must be used to repair the store before SFC can effectively fix system files. Scanning component store health identifies corruption, restoring health repairs the component store payload, running SFC scan replaces damaged system files using the restored store, and rebooting the machine completes the update for files locked during runtime.

Adım Adım Çözüm

1
Execute dism /online /cleanup-image /scanhealth
Checks the Windows component store for corruption and reports whether repairs are needed.
Scanning health establishes whether the component store image is damaged prior to attempting remediation.
2
Execute dism /online /cleanup-image /restorehealth
Downloads clean payload files to repair the local Windows Component Store image.
System File Checker requires a healthy Component Store to pull clean files when fixing operating system corruption.
3
Execute sfc /scannow
Scans protected system files and replaces corrupted files with clean copies from the restored component store.
Running SFC after DISM guarantees that SFC utilizes a verified, healthy source repository.
4
Restart the workstation
Applies file replacements for system binaries that were locked by active processes.
A system reboot is necessary to complete replacing locked operating system files.

Anahtar Kavram

Windows Command-Line System Repair Sequence (DISM and SFC)
Soru 190Soru

A financial analyst reports that a local database reporting application frequently freezes and crashes during heavy monthly report generation on a Windows workstation. Resource Monitor indicates that during report generation, the secondary storage drive (E:) exhibits a Disk Queue Length consistently exceeding 6 with an Average Response Time above 650 ms. Place the technician's troubleshooting and resolution steps in the correct chronological order from first to last.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The proper troubleshooting sequence begins with observing live performance metrics in Task Manager and Resource Monitor, inspecting Event Viewer for Event ID 1002 hang logs, executing chkdsk to rule out disk file system corruption, relocating the temporary scratch directory to an NVMe SSD, and finally executing a test report to verify system stability.
Following CompTIA troubleshooting methodology, the technician must first identify the problem by observing live symptoms (inspecting Task Manager and Resource Monitor for disk queue metrics), verify historical failure details in Event Viewer (Event ID 1002 AppHang), test volume health (chkdsk), implement the solution (reconfiguring scratch path to an NVMe drive), and verify full system functionality by testing report generation.

Adım Adım Çözüm

1
Identify live performance bottlenecks using Task Manager and Resource Monitor.
Discovers high disk active time, process I/O rates, and elevated disk queue lengths.
Initial troubleshooting requires gathering real-time diagnostic data directly from the running system.
2
Check the Event Viewer Application log for Event ID 1002.
Confirms the exact faulting application executable name and hang timestamp.
Correlating live metrics with system event logs confirms the precise nature of the application hang.
3
Execute chkdsk E: /f from an elevated command prompt.
Verifies file system integrity and repairs logical volume errors.
Ruling out disk corruption ensures the high response time is caused by performance limitations rather than file system damage.
4
Reconfigure application scratch paths to move temporary data onto NVMe storage.
Eliminates the mechanical disk I/O bottleneck by using high-throughput storage.
Remediating the root cause requires rehoming intensive I/O operations to adequate hardware.
5
Run a test workload and monitor performance counters.
Validates that disk queue length remains low and report generation succeeds without hangs.
CompTIA A+ methodology requires verifying full system functionality after implementing a fix.

Anahtar Kavram

CompTIA A+ Troubleshooting Methodology for Application Hangs and Disk Bottlenecks
Tahmini Süre:2m 0s
Soru 191Soru

A technician needs to repair corrupted startup boot files on a Windows system that displays a 'BOOTMGR is missing' error using Windows Recovery Environment (WinRE). How should the technician sequence the recovery process from start to finish?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence of recovery steps is: Boot from Windows Installation Media, open the Command Prompt via Troubleshooting options, run bootrec /fixmbr, run bootrec /fixboot, and finally run bootrec /rebuildbcd.
To systematically fix startup boot errors in Windows using WinRE, a technician must first boot from installation media, navigate to the Command Prompt in Troubleshooting, repair the Master Boot Record with bootrec /fixmbr, write a clean partition boot sector with bootrec /fixboot, and complete the repair by rebuilding the BCD file using bootrec /rebuildbcd.

Adım Adım Çözüm

1
Boot from Windows Installation Media
Access to Windows Setup and Repair options
External recovery media is required to access diagnostic tools when BOOTMGR is missing from the local disk.
2
Open Command Prompt in Advanced Options
WinRE Command Line environment opens
Manual execution of boot repair command utilities requires an administrative command prompt.
3
Run bootrec /fixmbr command
Master Boot Record is rewritten
Repairing the MBR resolves foundational drive partition boot record corruption.
4
Run bootrec /fixboot command
New system partition boot sector is created
Writing a fresh boot sector allows the partition to correctly load the BOOTMGR executable.
5
Run bootrec /rebuildbcd command
BCD store is updated with recognized Windows installations
Scanning drives and rebuilding the Boot Configuration Data store ensures the boot manager finds valid OS boot entries.

Anahtar Kavram

Windows Boot Troubleshooting Sequence
Soru 192Soru

A smartphone user reports that an augmented reality navigation application causes severe thermal throttling and rapid battery drain even after navigating away from the app. Following standard CompTIA mobile OS troubleshooting methodology, place the following actions in the correct sequence from least invasive to most invasive.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence from least invasive to most invasive is: 1. Force close the navigation application using the OS task switcher or application settings. 2. Perform a soft reset by restarting the mobile device. 3. Uninstall and reinstall the navigation application from the official app store. 4. Perform a factory reset to restore the mobile device to default settings.
CompTIA troubleshooting methodology requires technicians to start with the least invasive step (force stopping the application), progress to non-destructive system reboots (soft reset), attempt application-level remediation (uninstall/reinstall), and end with destructive system recovery options (factory reset).

Adım Adım Çözüm

1
Identify the immediate least invasive action that targets only the misbehaving process.
Force closing the application stops background processor utilization without affecting other system resources or data.
Always isolate and terminate the specific software process before performing system-level or destructive operations.
2
Escalate to a non-destructive system-level restart if app closure does not resolve OS instability.
A soft reset flushes system RAM and restarts core OS services.
Rebooting clears temporary system glithes while preserving all installed apps and stored user data.
3
Target software corruption by replacing application files.
Uninstalling and reinstalling clears corrupted application files and cache while retaining overall OS configuration.
Reinstalling the app isolates application-layer file corruption before considering OS-level wipes.
4
Apply the final fallback measure if all non-destructive troubleshooting steps fail.
A factory reset wipes all data and restores the operating system to factory defaults.
Destructive steps that require data recovery and reconfiguration must always be reserved as the last resort.

Anahtar Kavram

Least Invasive to Most Invasive Mobile OS Troubleshooting Methodology
Soru 193Soru

A Windows 11 workstation utilizing a UEFI partition scheme fails to boot, displaying a blue screen with the error code 0xc000000f stating that the Boot Configuration Data (BCD) file is missing required information. A system administrator boots the system into the Windows Recovery Environment (WinRE) and opens the Command Prompt. Place the technician's recovery steps in the correct order to assign a temporary drive letter to the hidden EFI System Partition (ESP) and rebuild the BCD store.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence starts by opening Diskpart and listing volumes to locate the hidden FAT32 partition, selecting that volume and assigning it drive letter V:, exiting Diskpart to navigate to V:\EFI\Microsoft\Boot\, renaming the corrupted bcd file to bcd.old, and finally executing the bcdboot C:\Windows /s V: /f UEFI command to generate new boot files.
On UEFI systems, startup repair requires mounting the hidden FAT32 EFI System Partition via Diskpart. Once a letter is assigned, the technician must exit Diskpart to access the directory containing the BCD, rename the corrupt file so it does not block reconstruction, and run the bcdboot command referencing the Windows directory, target drive letter, and UEFI firmware type.

Adım Adım Çözüm

1
Use Diskpart to identify the hidden EFI System Partition (ESP).
Discovers the specific volume formatted in FAT32 (typically around 100MB-500MB) that holds boot files.
On UEFI/GPT systems, boot files reside on a hidden partition without a default assigned drive letter.
2
Select the volume and assign a temporary drive letter (e.g., V:).
The hidden ESP becomes accessible via drive letter V:.
Command-line repair utilities require a valid drive path to modify or replace system boot files on the ESP.
3
Exit Diskpart and change working directory to V:\EFI\Microsoft\Boot\.
The terminal focus shifts directly to the location of the existing BCD file.
Operating within the boot directory allows manual backup and modification of boot files.
4
Rename the existing corrupt BCD store using ren bcd bcd.old.
The damaged BCD file is renamed, clearing the path for creating a clean BCD configuration.
If a damaged BCD file remains named 'bcd', repair utilities like bootrec or bcdboot may fail to overwrite it.
5
Run bcdboot C:\Windows /s V: /f UEFI.
Fresh system boot files and a valid BCD structure are created on the target volume.
The bcdboot utility extracts functional boot files from the main Windows OS installation directory and configures the UEFI bootloader properly.

Anahtar Kavram

Troubleshooting UEFI/GPT Windows OS Startup Errors via WinRE Command Line
Tahmini Süre:2m 30s
Soru 194Soru

A helpdesk technician is responding to an incident involving a Windows workstation infected with a persistent crypto-mining Trojan. The malware infection has already been identified and verified by security logs. Place the following remediation actions in the correct sequence according to the official CompTIA 7-step malware removal process.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct chronological sequence following the CompTIA 7-step malware removal methodology is: 1) Disconnect the computer from networks (Quarantine), 2) Disable System Restore, 3) Update anti-malware signatures and scan in Safe Mode (Remediate), 4) Re-enable System Restore and create a clean restore point, and 5) Educate the end user.
The standard CompTIA 7-step malware removal process follows a specific lifecycle: 1. Identify malware symptoms, 2. Quarantine infected systems, 3. Disable System Restore, 4. Remediate infected systems (a. Update anti-malware software, b. Scan and use removal techniques), 5. Schedule updates and enable automated scans, 6. Enable System Restore and create a restore point, 7. Educate the end user. Arranging the actions from isolation (quarantine) through disabling System Restore, updating/scanning, re-enabling System Restore, and finishing with user training strictly satisfies this workflow.

Adım Adım Çözüm

1
Isolate the compromised system (Quarantine)
Network communication is severed, preventing malware proliferation.
CompTIA Step 2 dictates quarantining the infected system immediately after identification.
2
Disable System Restore
Corrupted restore points containing infected system files are deleted.
CompTIA Step 3 requires disabling System Restore prior to scanning so malware cannot survive via system rollbacks.
3
Remediate infected system
Anti-malware signatures are updated and the crypto-mining Trojan is identified and deleted in Safe Mode.
CompTIA Step 4 specifies updating anti-malware engine definitions and using scan/removal tools.
4
Re-enable System Restore and create a restore point
A clean recovery baseline is established after ensuring the system is clean and scheduled updates are set.
CompTIA Step 6 restores system protection functionality once remediation is successful.
5
Educate the end user
The end user learns preventative practices to lower the risk of reinfection.
CompTIA Step 7 concludes the remediation lifecycle with end-user security training.

Anahtar Kavram

CompTIA 7-Step Malware Removal Process
Soru 195Soru

A systems administrator needs to harden a standalone Windows 11 workstation by configuring User Account Control (UAC) to automatically deny all elevation prompts for standard domain users. Place the steps in the correct order to accomplish this configuration using the Local Security Policy snap-in.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence begins with opening secpol.msc, navigating to Security Settings > Local Policies > Security Options, selecting 'User Account Control: Behavior of the elevation prompt for standard users', setting the option to 'Automatically deny elevation requests', and executing gpupdate /force to apply the changes immediately.
Configuring UAC behavior policies on a Windows workstation requires launching secpol.msc to access Local Policies > Security Options. Modifying 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' ensures standard users cannot elevate privileges. Executing gpupdate /force enforces the updated policy immediately.

Adım Adım Çözüm

1
Launch the management tool
Local Security Policy console opens
Administrative privilege and UAC security policies are configured in secpol.msc.
2
Navigate to the Security Options branch
Security Options policies are listed
Security Options contains fine-grained UAC behavior settings.
3
Open the standard user elevation policy
Policy properties configuration dialog appears
Targeting the specific setting controlling standard user privilege elevation.
4
Select 'Automatically deny elevation requests'
Standard user elevation prompts are suppressed and blocked
This satisfies the requirement to suppress credential prompts and prevent unauthorized elevation.
5
Run gpupdate /force in Command Prompt
Policy update completes successfully
Ensures immediate policy enforcement across the system.

Anahtar Kavram

Configuring User Account Control (UAC) security policies using Local Security Policy (secpol.msc)
Tahmini Süre:1m 30s
Soru 196Soru

A technician is troubleshooting a Windows workstation where a desktop productivity application freezes immediately upon launch. What is the correct sequence of steps the technician should take to isolate and resolve the issue?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The technician should first terminate the unresponsive process in Task Manager, review the Application log in Event Viewer for faulting module details, execute a Clean Boot to isolate background software conflicts, and finally repair or reinstall the application.
The proper troubleshooting methodology dictates stabilizing the system first by ending the unresponsive process in Task Manager, analyzing historical log data in Event Viewer to pinpoint the faulting module, using a Clean Boot to rule out third-party application interference, and finally repairing or reinstalling the application if corrupted files are confirmed.

Adım Adım Çözüm

1
Terminate hung application
System resources are freed and the system returns to an operable state.
Before investigating logs or modifying settings, the active frozen process must be ended.
2
Examine Event Viewer Application logs
Identifies Event ID 1000 and the specific faulting module or DLL.
Reviewing historical crash data provides direct evidence of the crash cause.
3
Perform a Clean Boot via msconfig
Windows boots with only essential Microsoft services running.
Isolates whether the crash is caused by third-party background software or startup items.
4
Repair or reinstall application
Replaces damaged application binaries and registry entries.
Final remediation action to fix corrupted installation files.

Anahtar Kavram

Standard Windows Application Crash Isolation Workflow
Soru 197Soru

A technician is troubleshooting a Windows 11 workstation where a custom line-of-business inventory application frequently freezes during database synchronization. Place the following diagnostic and remediation steps in the correct sequential order to analyze the active frozen state, inspect crash logs, review system stability history, and repair operating system files.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct troubleshooting order begins with analyzing the active process wait chain in Task Manager, followed by inspecting Event Viewer application hang logs, checking Reliability Monitor for system change history, and finally running System File Checker to repair corrupted operating system files.
The correct troubleshooting sequence follows the standard CompTIA methodology: gather live diagnostic data first (Task Manager Analyze Wait Chain), review application event log specifics (Event Viewer Event ID 1002), review timeline correlation with recent updates (Reliability Monitor), and perform file integrity repair (sfc /scannow).

Adım Adım Çözüm

1
Analyze the active process state using Task Manager's Analyze Wait Chain feature.
Identifies if the application process is blocked by another process or thread.
Immediate live diagnostic tools take priority when an application is currently frozen.
2
Examine Event Viewer Application logs for Event ID 1002.
Provides exact faulting module names and failure signatures.
Detailed application log analysis clarifies specific technical error codes.
3
Review Reliability Monitor trends.
Correlates the onset of crashes with software or driver installations.
Evaluating environmental changes helps isolate external factors causing the performance degradation.
4
Execute sfc /scannow in an elevated Command Prompt.
Scans and repairs damaged operating system files and libraries.
System repair commands should be run after diagnosing and establishing the likely root cause.

Anahtar Kavram

Methodological Troubleshooting of Windows Performance and Application Hangs
Soru 198Soru

A technician is troubleshooting a desktop workstation that fails to complete POST and emits a continuous beep code immediately after a memory upgrade. Place the following troubleshooting steps in the correct sequence to isolate the issue according to standard CompTIA hardware diagnostic procedures.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence begins with disconnecting AC power and draining residual electricity, removing the newly installed RAM module to re-establish a baseline, powering on the system to verify baseline operation, and finally testing the new RAM module independently in a known-good slot.
CompTIA hardware troubleshooting principles mandate establishing safety first by removing power and draining residual charge, returning to a known-good baseline by removing newly added RAM, verifying baseline system operation, and then testing the new module independently to isolate component versus slot failure.

Adım Adım Çözüm

1
Disconnect AC power and drain residual motherboard voltage.
Prevents electrical discharge damage and hazards during component handling.
Safety procedures mandate de-energizing the power supply unit and clearing capacitors before working inside the chassis.
2
Remove the newly added RAM module to establish a baseline.
Isolates the new hardware variable from the system.
Standard troubleshooting methodology dictates undoing recent hardware modifications first.
3
Reconnect power and verify baseline POST.
Determines whether original hardware functions without emitting beep codes.
Confirms system health under pre-existing hardware conditions.
4
Test the new module separately in a known-good DIMM slot.
Pinpoints whether the failure is caused by a bad RAM module or a damaged motherboard slot.
Isolated hardware testing reveals the exact root cause of the error.

Anahtar Kavram

Isolating Memory POST Failures using Systematic Component Testing
Tahmini Süre:1m 30s
Soru 199Soru

A desktop support technician is deploying a legacy 32-bit local database application on a 64-bit Windows 11 workstation. The application requires a system-wide database connection and access to shared local data files for standard domain users. Which sequence of administrative steps should the technician perform to properly configure the application and verify user access?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct procedural order is: first, launch the 32-bit ODBC Data Source Administrator executable from C:\Windows\SysWOW64\odbcad32.exe; second, create a System DSN using the target 32-bit database driver; third, set Read and Write NTFS permissions for standard domain users on the shared directory in C:\ProgramData; and fourth, sign in with a standard domain user account to verify application connectivity and file access.
Configuring legacy 32-bit software on a 64-bit operating system requires using the SysWOW64 directory path to access 32-bit utilities like odbcad32.exe. Creating a System DSN ensures all local profiles share the connection configuration. Setting Read/Write permissions on C:\ProgramData accommodates shared application state files without granting full administrative privileges, and final testing under a standard user account verifies the setup under least-privilege conditions.

Adım Adım Çözüm

1
Open the 32-bit ODBC Data Source Administrator.
The 32-bit ODBC management tool launches, exposing 32-bit database drivers installed on the 64-bit Windows system.
Windows 64-bit operating systems use C:\Windows\SysWOW64\odbcad32.exe for 32-bit database architecture administration. Using System32 would launch the 64-bit tool, which cannot configure 32-bit drivers.
2
Create a System DSN.
A system-wide Data Source Name is established.
System DSNs store connection parameters in the registry under HKEY_LOCAL_MACHINE, making the database connection available to all workstation users.
3
Configure NTFS access control lists (ACLs) on C:\ProgramData\ApplicationFolder.
Standard users gain the necessary privileges to read and write shared data files.
By default, C:\ProgramData grants Read access to standard users. Since database applications require writing to data files, explicit Write permissions must be granted.
4
Perform end-user functional testing.
Application configuration and permission inheritance are validated in the actual production execution context.
Testing must be conducted under a non-administrative account to confirm that User Account Control (UAC) or permission restrictions will not block standard users.

Anahtar Kavram

32-bit vs 64-bit Application Compatibility and Folder Permission Hierarchy
Soru 200Soru

An IT technician is dispatched to troubleshoot a desktop inkjet printer that is producing printed documents with missing horizontal lines and faded colors. Arrange the technician's troubleshooting steps in the correct sequence according to the standard CompTIA troubleshooting methodology, from first step to last step.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct troubleshooting sequence follows the standard CompTIA 6-step methodology: 1) Gather details and inspect output to identify the problem, 2) Formulate a theory that dried ink has clogged the printhead nozzles, 3) Test the theory by printing a diagnostic nozzle check pattern, 4) Implement the solution by running a printhead cleaning cycle and alignment, and 5) Verify full functionality with a test page and document the resolution in the support ticket.
The correct order strictly adheres to the official CompTIA 6-step troubleshooting methodology: first identifying the problem through user inquiry and symptom inspection, second establishing a theory of dried ink nozzle blockage, third testing that theory with a diagnostic print grid, fourth implementing the solution via printhead cleaning software, and fifth verifying functionality with a test page while documenting outcomes.

Adım Adım Çözüm

1
Identify the problem
Technician gathers information from the user and inspects physical print defects.
CompTIA methodology requires defining the scope and nature of the issue before forming conclusions.
2
Establish a theory of probable cause
Technician identifies printhead nozzle clogging as the most likely root cause for missing horizontal bands.
Developing a probable cause guides targeted diagnostic testing.
3
Test the theory to determine cause
Technician prints a nozzle check test grid to visually confirm missing ink flows.
Empirical testing validates whether the theory is correct prior to performing corrective repairs.
4
Establish a plan of action and implement the solution
Technician performs printhead cleaning cycles and alignment routines.
Implementing the corrective action resolves the underlying hardware issue.
5
Verify full system functionality and document findings
Technician verifies crisp output with a test page and logs the fix in the ticketing system.
Ensures the system is completely operational and maintains institutional knowledge for future issues.

Anahtar Kavram

CompTIA Troubleshooting Methodology for Inkjet Print Quality Issues
ÖncekiSayfa 10 / 22Sonraki
Tüm alıştırma soruları — CompTIA A+ (Core 1 & Core 2) | Examkin