Tüm alıştırma soruları

3551 soru

Soru 2661Soru

A user reports that a specialized accounting application on a Windows 11 workstation crashes unexpectedly every time a monthly summary report is generated. The application closes immediately upon completion of data compilation without displaying an on-screen error message. Which TWO of the following initial diagnostic actions should a technician perform to isolate and investigate the root cause of these application crashes? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Review Reliability Monitor to correlate the timeline of application failures with recent updates, patches, or driver installations.; Examine Windows Event Viewer Application logs for Event ID 1000 entries to identify the faulting application name and module path.

Cevap

The correct actions are reviewing Reliability Monitor to correlate failures with recent system updates, and examining Windows Event Viewer Application logs for Event ID 1000 to identify the faulting module.
Analyzing system stability history in Reliability Monitor helps determine if recent software updates coincide with the crashes. Checking Event Viewer Application logs for Event ID 1000 provides the specific faulting application executable and faulting DLL module, allowing targeted troubleshooting.

Adım Adım Çözüm

1
Check event history using built-in Windows diagnostics
Reliability Monitor displays a stability index timeline showing recent software updates and crash occurrences side-by-side.
This establishes whether the crashes started following a specific configuration change or update.
2
Inspect technical crash details in Event Viewer
Event ID 1000 in the Application log reveals the exact faulting executable or DLL module.
Identifying the specific module isolate whether a dependent DLL or main application executable is failing.

Anahtar Kavram

Application Crash Diagnosis and Log Analysis
Soru 2662Soru

An IT security technician is auditing embedded smart badge reader terminals installed at corporate building entry points. The audit reveals that the readers communicate directly on the main internal employee network and retain default administrative passwords. Which of the following actions should the technician implement FIRST to harden these embedded systems and reduce network risk?

Cevabı ve açıklamayı göster

Cevap: Segment the embedded devices onto an isolated network VLAN and update default administrative credentials.

Cevap

Segment the embedded devices onto an isolated network VLAN and update default administrative credentials.
Proper security hardening for embedded and IoT devices requires immediately changing default administrative credentials and placing the devices on an isolated network segment (VLAN). This prevents unauthorized login attempts and mitigates lateral movement into the primary corporate network.

Adım Adım Çözüm

1
Analyze identified embedded system vulnerabilities
The embedded badge readers retain factory default passwords and reside directly on the internal LAN.
Embedded IoT devices typically lack standard anti-malware agents, making default credentials and flat network placement major security risks.
2
Apply targeted security controls for embedded systems
Updating default credentials eliminates easy administrative compromise, while placing the devices on an isolated VLAN restricts lateral network movement.
Network isolation ensures that an exploited embedded endpoint cannot be used as a pivot point to reach sensitive corporate infrastructure.

Anahtar Kavram

Embedded System Hardening and Network Isolation
Soru 2663Soru

A cybersecurity technician is establishing baseline operational policies for workstation security across an enterprise network. Match each workstation hardening control on the left with the primary security risk it directly mitigates on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Disabling unneeded operating system services
Configuring account lockout threshold rules
Enforcing password-protected screen saver timeouts
Disabling AutoRun and AutoPlay policies

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Matching pairs: Disabling unneeded OS services matches reducing attack surface by closing network listening ports; Account lockout thresholds match mitigating online brute-force password attacks; Password-protected screen saver timeouts match preventing unauthorized physical access to unattended terminals; Disabling AutoRun and AutoPlay policies matches blocking automatic script execution from plugged-in storage drives.
Each security control targets a specific vulnerability vector: disabling unnecessary services minimizes open ports and attack surface; account lockout policies defend against automated brute-force login attempts; enforcing screen saver password locks guards against local unauthorized access to unattended desktops; and turning off AutoRun/AutoPlay stops rogue USB drives from auto-launching malicious software.

Adım Adım Çözüm

1
Analyze service disabling hardening principles
Disabling unnecessary services stops background listeners and unused system daemons.
Eliminating running processes directly shrinks the workstation's attack surface and closes listening ports.
2
Evaluate account security policies
Account lockout thresholds limit consecutive incorrect password attempts.
Locking out accounts after repeated failures thwarts automated password-guessing and brute-force tools.
3
Assess physical display access controls
Screen saver timeout locking requires credentials to resume session access.
Secures active sessions from walk-up physical access when users leave their desk.
4
Examine removable storage media policies
Disabling AutoRun/AutoPlay blocks automatic launcher script execution upon media connection.
Stops malicious payloads stored on USB flash drives from executing automatically without user interaction.

Anahtar Kavram

Workstation Hardening Controls and Risk Mitigation Mapping
Soru 2664Soru

A systems administrator detects active ransomware activity on a master workstation controlling live digital media encoding streams in a television broadcasting studio. Following the standard CompTIA 7-step malware removal process, in what precise chronological sequence should the administrator perform the following remediation steps?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The proper sequence follows the CompTIA 7-step malware removal methodology: First, isolate the system by disconnecting network interfaces; second, disable System Restore and delete previous restore points; third, remediate the workstation by updating definitions offline and scanning in Safe Mode; fourth, re-enable System Restore and generate a clean restore point; fifth, educate the end user on security best practices.
CompTIA mandates a strict 7-step malware removal process: 1. Identify malware symptoms, 2. Isolate infected systems, 3. Disable System Restore, 4. Remediate infected systems (update anti-malware and scan), 5. Schedule scans and run updates, 6. Enable System Restore and create a restore point, and 7. Educate end user. Network isolation must precede all remediation to halt lateral propagation. Disabling System Restore deletes infected recovery snapshots. Remediating eradicates the active infection. System Restore is re-enabled only when the system is verified clean, followed finally by user education.

Adım Adım Çözüm

1
Isolate the infected workstation by disconnecting all wired and wireless network interfaces.
Prevents ransomware from communicating with command-and-control servers or spreading across network shares.
System isolation is Step 2 of CompTIA's process and must occur immediately after threat identification.
2
Disable Windows System Restore and delete existing restore snapshots.
Eliminates malware persistence mechanisms embedded in volume shadow copies.
Disabling System Restore is Step 3, preventing the system from automatically backing up infected files.
3
Boot into Safe Mode, apply offline anti-malware updates, and complete a full system scan.
Detects and quarantines active ransomware binaries and startup entries without active network reinfection.
System remediation is Step 4, using updated tools in a minimal environment to clear threats.
4
Turn System Restore back on and manually build a new clean system restore point.
Restores OS protection functionality with a confirmed malware-free recovery point.
Enabling System Restore is Step 6 and must strictly take place after successful scan remediation.
5
Provide targeted security awareness training to the broadcast engineer.
Improves user vigilance against social engineering, malicious email links, and drive-by downloads.
End-user education is Step 7, completing the malware remediation workflow.

Anahtar Kavram

CompTIA 7-Step Malware Removal Best Practices
Soru 2665Soru

Following a hard drive replacement on a legacy MBR-based system, a technician restores a Windows 10 disk image to the new drive. Upon restarting, the system fails to load the operating system and displays a black screen stating 'BOOTMGR is missing'. Launching the Windows Recovery Environment (WinRE) Command Prompt reveals that the system partition is not flagged to boot and the Master Boot Record code is corrupted. Which TWO procedures should the technician execute from the WinRE command-line interface to resolve this boot failure? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Run bootrec /fixmbr to rewrite the Master Boot Record on the system partition.; Use the diskpart tool to select the system partition and execute the active command.

Cevap

The correct procedures are executing 'bootrec /fixmbr' to repair the Master Boot Record and using 'diskpart' to mark the system partition as active.
On MBR legacy BIOS systems displaying 'BOOTMGR is missing' after disk imaging, two essential fixes are marking the target system partition as 'active' via diskpart so the BIOS identifies where boot code resides, and running 'bootrec /fixmbr' to write clean master boot code to the disk.

Adım Adım Çözüm

1
Identify the cause of the 'BOOTMGR is missing' error on an MBR system.
Recognize that both an invalid/inactive boot partition flag and corrupted MBR boot code prevent the system BIOS from finding the BOOTMGR file.
On legacy MBR setups, BIOS hands control to the MBR, which looks for the partition marked active to execute BOOTMGR.
2
Flag the system partition as active using DiskPart in WinRE.
Run diskpart, list/select the system volume, and issue the 'active' command to set the bootable flag.
Without an active partition, the system cannot locate the bootloader binaries upon system initialization.
3
Repair the Master Boot Record code using the Bootrec utility.
Execute 'bootrec /fixmbr' in the WinRE command prompt.
Writing a clean Master Boot Record fixes corrupted boot sector instructions without damaging partition table structures.

Anahtar Kavram

Legacy MBR Windows Startup Repair
Soru 2666Soru

A systems administrator at a municipal transit operations center is following the standard CompTIA seven-step malware remediation workflow to resolve a malware infection on a Windows workstation. The administrator has already quarantined the machine, disabled System Restore, updated anti-malware signatures, scanned and removed the malicious files, and configured scheduled automatic scans and updates. Which step should the administrator perform NEXT?

Cevabı ve açıklamayı göster

Cevap: Enable System Restore and create a new restore point.

Cevap

Enable System Restore and create a new restore point.
The correct response is to enable System Restore and create a new restore point. In the CompTIA 7-step malware remediation process, Step 6 requires technicians to re-enable System Restore and create a fresh restore point after the system has been cleaned (Step 4) and automatic updates/scans have been scheduled (Step 5). This ensures the OS has a known-good recovery point free of malware infections.

Adım Adım Çözüm

1
Review the completed steps in the CompTIA 7-step malware remediation process.
Steps 1 through 5 (Identify, Quarantine, Disable System Restore, Remediate/Scan, Schedule Updates/Scans) are verified as complete.
Tracking current remediation progress ensures steps are executed in the mandated sequence.
2
Identify the next sequential step following Step 5 (Schedule updates and run scans).
Step 6 is to Enable System Restore and create a new restore point.
System Restore was disabled earlier to prevent reinfection from corrupted restore points; re-enabling it now creates a clean post-remediation baseline.
3
Confirm the remaining step.
Step 7 (Educate the end user) will be performed after Step 6.
Creating a clean restore point must happen before final user handoff and education.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Best Practices
Tahmini Süre:1m 0s
Soru 2667Soru

A desktop support technician at an automotive assembly plant is responding to a workstation infected with rogue adware causing unexpected browser redirects. The technician has already identified and researched the malware symptoms. Arrange the subsequent remediation actions in the correct chronological order according to the standard CompTIA 7-step malware removal process.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence follows the CompTIA 7-step malware remediation process: first quarantine the infected workstation, then disable System Restore, proceed with updating definitions and scanning for malware removal, re-enable System Restore and create a clean restore point, and finish by educating the end user.
The standard CompTIA 7-step malware removal framework mandates the following exact order: 1. Identify malware symptoms, 2. Quarantine infected systems, 3. Disable System Restore, 4. Remediate infected systems (update anti-malware definitions and scan/remove), 5. Schedule updates and enable auto-scans, 6. Enable System Restore and create a restore point, and 7. Educate the end user. The sequence from isolating the system to educating the user adheres strictly to this standard.

Adım Adım Çözüm

1
Quarantine the infected workstation
Network communication is terminated, isolating the rogue adware from the rest of the assembly plant network.
Step 2 of the CompTIA process prevents malware from spreading or contacting command-and-control servers.
2
Disable Windows System Restore
Existing restore points containing malicious files are deleted.
Step 3 prevents accidental reinfection if a restore point is restored in the future.
3
Update anti-malware signatures and perform full system scan
The rogue adware is identified and completely removed from the host.
Step 4 performs the core remediation and file cleanup using updated detection definitions.
4
Re-enable System Restore and create a fresh restore point
A clean, verified system baseline snapshot is preserved.
Step 6 re-establishes system protection only after verifying the machine is clean.
5
Educate the end user
The user learns best practices to prevent similar infections.
Step 7 is the final administrative action to reduce human security vulnerabilities.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process
Tahmini Süre:1m 30s
Soru 2668Soru

A systems administrator is configuring endpoint security profiles for enterprise mobile devices and specialized embedded hardware. Which mobile and embedded security control correctly matches each operational requirement?

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Containerization
Geofencing
Selective Wipe
Network Segmentation

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Containerization matches isolating corporate apps into an encrypted sandbox on personal endpoints. Geofencing matches restricting features based on GPS or location data. Selective wipe matches removing corporate files while preserving personal user data. Network segmentation matches placing legacy IoT sensors onto an isolated VLAN.
Containerization logically segregates enterprise software from personal data; Geofencing triggers location-based security policies via GPS or radio signals; Selective wipe targets company data for deletion without affecting user content; and Network segmentation isolates vulnerable embedded systems on segregated network zones.

Adım Adım Çözüm

1
Identify the mechanism that segregates work content on personal devices.
Containerization creates a distinct secure workspace on BYOD endpoints.
Containerization ensures corporate data is segregated and encrypted separately from personal user content.
2
Identify the technology enforcing location-aware security restrictions.
Geofencing dynamically adjusts security options based on device coordinates.
Geofencing relies on location metrics (GPS/cellular) to apply site-specific rules.
3
Identify the command used to clean business records from departing employee endpoints.
Selective wipe removes managed enterprise assets while leaving personal assets unaffected.
MDM selective wipe actions target corporate containers without affecting user storage.
4
Identify the security approach suited for embedded or IoT hardware.
Network segmentation restricts embedded device network exposure.
Because IoT devices often lack endpoint antimalware agents, isolating them on separate VLANs prevents lateral threat movement.

Anahtar Kavram

Mobile Device and Embedded System Security Controls
Soru 2669Soru

A desktop technician is configuring a client-side hypervisor to host multiple virtual machines on a host workstation with limited physical drive space. To conserve physical storage upon initial creation while allowing the guest OS to expand its storage footprint as needed up to a set threshold, which virtual disk provisioning method should the technician configure?

Cevabı ve açıklamayı göster

Cevap: Thin provisioning (dynamically allocated disk)

Cevap

Thin provisioning (dynamically allocated disk) is the correct choice because it consumes physical host storage space on demand as data is added, rather than pre-allocating the full virtual capacity.
Thin provisioning (dynamically allocated disk) creates a virtual disk file that initially uses only a small amount of physical host storage space for metadata and grows on-demand as data is written by the guest operating system, fitting the scenario's requirement for minimal initial host drive consumption.

Adım Adım Çözüm

1
Analyze the storage constraint and operational requirement.
The host workstation has limited physical drive space and needs to run VMs whose physical disk footprint grows only as data is added.
Pre-allocating storage would instantly consume scarce host disk space.
2
Evaluate hypervisor virtual disk provisioning types.
Thin provisioning (dynamically allocated) allocates space on the physical host storage only when block writes occur in the guest OS.
This minimizes the initial physical storage footprint while supporting expansion up to the assigned ceiling.

Anahtar Kavram

Virtual Disk Provisioning and Host Resource Optimization
Tahmini Süre:1m 15s
Soru 2670Soru

A tier-2 desktop analyst is remediating a confirmed rootkit and spyware infection on a dedicated workstation at a financial services firm. The analyst has already completed the initial identification of malware symptoms and fully isolated the workstation from the corporate network. According to CompTIA's standard malware removal procedures, which of the following actions should the analyst perform NEXT prior to running local remediation and scanning tools? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Disable System Restore in Windows to prevent infected files from being stored in recovery snapshots.; Obtain updated anti-malware definition files from a uncompromised machine and apply them locally via removable media.

Cevap

The specialist must disable System Restore to prevent infected files from persisting in recovery points, and update anti-malware signatures locally using clean removable media while keeping the machine isolated.
Following system isolation (Step 2), the compulsory actions before running anti-malware removal tools (Step 4b) are to turn off/disable System Restore (Step 3) to prevent saving infected files into restore snapshots, and to update anti-malware signatures (Step 4a) out-of-band via clean external storage media to preserve isolation.

Adım Adım Çözüm

1
Review current progress in the 7-step malware removal process.
Steps 1 (Identify malware symptoms) and 2 (Isolate infected systems) are complete.
Determines the immediate next mandatory steps in sequence.
2
Disable System Restore (Step 3).
All existing restore points are purged and no new infected points are created.
Prevents malware from lingering in system volume information or being restored inadvertently.
3
Update anti-malware software out-of-band (Step 4a).
Signatures are updated locally without reconnecting the compromised host to the network.
Prepares the anti-malware tool to accurately detect and remove recent threat variants while maintaining complete network isolation.

Anahtar Kavram

CompTIA 7-Step Malware Removal Process
Soru 2671Soru

A user on a Windows 11 workstation reports that entering standard URLs into the web browser automatically redirects to an external promotional search engine. Additionally, intrusive pop-up windows display continuously, even when visiting trusted internal sites. Further inspection reveals that an unauthorized extension altered browser defaults and local host resolution has been tampered with. Which of the following remediation actions should the technician perform to address these issues? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Remove the unauthorized browser extension and reset browser configuration settings to default.; Inspect the local Windows hosts file and clear any unauthorized static IP mapping entries.

Cevap

The technician should remove the unauthorized browser extension and reset browser settings, as well as inspect and clean unauthorized IP mappings from the local Windows hosts file.
Resolving browser hijacks and unauthorized pop-ups requires tackling both application-level components (removing malicious extensions and resetting configuration defaults) and OS-level redirection vectors (clearing unauthorized entries in the local hosts file).

Adım Adım Çözüm

1
Identify browser hijack vectors
Discovered rogue extension and persistent browser redirects.
Unauthorized browser extensions can override homepages, search engines, and security settings.
2
Remove malicious browser add-ons and reset configuration
Restored original browser behavior and blocked pop-up scripts.
Resetting browser settings to default removes policy overrides and disables untrusted extensions.
3
Check system-level redirection mechanisms
Identified and removed malicious static entries in C:\Windows\System32\drivers\etc\hosts.
Host file entries override DNS resolution and cause domain redirects independent of browser settings.

Anahtar Kavram

Web Browser Hijacking and Local Name Resolution Troubleshooting
Soru 2672Soru

A desktop technician at a biopharmaceutical research laboratory is remediating a Windows 11 workstation infected with a trojan. The technician has already disconnected the computer from the network to quarantine the system and has disabled System Restore. Which of the following actions should the technician perform NEXT as part of the standard malware remediation process? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Update the anti-malware software definitions and signature files.; Perform a full system scan using anti-malware tools to remediate infected files.

Cevap

The technician should update the anti-malware software definitions and perform a full system scan to remediate the infected files.
According to the CompTIA 7-step malware remediation process, once the system is quarantined and System Restore is disabled, Step 4 requires remediating the system. Remediation consists of updating anti-malware definitions followed by conducting a full anti-malware scan to remove the threat.

Adım Adım Çözüm

1
Review the current state within the CompTIA 7-step malware remediation process.
Step 1 (Identify malware symptoms), Step 2 (Quarantine system), and Step 3 (Disable System Restore) have already been completed.
Understanding the current stage establishes what specific actions logically follow.
2
Identify the immediate next stage, which is Step 4 (Remediate the infected system).
Step 4 consists of two sub-steps: 4a (Update anti-malware signatures) and 4b (Scan and use removal techniques).
Remediation requires current threat signatures before scanning and cleaning infected files.
3
Select the option pairs that correspond to Step 4 sub-steps.
Updating anti-malware definition files and executing a full anti-malware system scan represent the required actions.
These actions directly carry out the remediation phase before scans are scheduled or System Restore is re-enabled.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process (Remediation Phase)
Soru 2673Soru

An IT security specialist is responding to an incident involving a Windows 11 Enterprise workstation used by a senior financial auditor. The system displays unauthorized browser redirects, altered proxy settings, and an unidentified background process named `syshost32.exe` consuming significant memory. The specialist has already completed symptom identification and fully isolated the workstation from all local and wireless networks. According to CompTIA's standard 7-step malware remediation procedure, which action should the specialist perform NEXT prior to executing remediation scans or updates?

Cevabı ve açıklamayı göster

Cevap: Disable System Protection (System Restore) in Windows to prevent infected state backups from persisting.

Cevap

Disable System Protection (System Restore) in Windows to prevent infected state backups from persisting.
In the standard CompTIA 7-step malware removal model, the sequence is: 1. Identify malware symptoms, 2. Isolate infected systems, 3. Disable System Restore (in Windows), 4. Remediate infected systems, 5. Schedule scans and run updates, 6. Enable System Restore and create a restore point, 7. Educate the end user. Since symptoms have been identified and isolation is complete, the mandatory next step is to disable System Restore.

Adım Adım Çözüm

1
Review the current progress within the CompTIA 7-step malware removal workflow.
Step 1 (Identify malware symptoms) and Step 2 (Isolate infected systems) have already been completed.
The technician confirmed rogue processes/redirects and disconnected all network connections.
2
Determine the mandatory next step in the procedure.
Step 3 dictates turning off System Restore (System Protection) in Windows.
Disabling System Restore purges existing restore points so malicious binaries archived in shadow copies cannot survive or be restored later.
3
Verify why alternative actions are premature or incorrect.
Updating anti-malware signatures or reconnecting to VLANs breaches isolation or prematurely skips Step 3.
Remediation (Step 4) must occur only after System Restore is disabled and isolation is strictly maintained.

Anahtar Kavram

CompTIA 7-Step Malware Removal Procedure order: Identify, Isolate, Disable System Restore, Remediate, Schedule Scans/Updates, Enable System Restore, Educate User.
Tahmini Süre:1m 15s
Soru 2674Soru

A system administrator is deploying core network services for a newly opened office branch. The network requires automatic distribution of IP address configurations to connecting workstations, as well as local resolution of human-readable device names to IP addresses without relying on external internet routing. Which TWO server roles must be installed and configured to meet these operational requirements? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: DHCP server to dynamically assign IP addresses, subnet masks, and default gateways to client devices; DNS server to maintain local database records that map internal hostnames to their respective IP addresses

Cevap

The DHCP server and DNS server roles.
Deploying a DHCP server fulfills the requirement to dynamically issue IP configuration parameters to workstations upon network connection. Deploying a DNS server satisfies the requirement for local name resolution by mapping hostnames to IP addresses within the office network.

Adım Adım Çözüm

1
Identify the service required for dynamic IP allocation.
The DHCP server role is responsible for automatically assigning network configurations, including IP addresses, subnet masks, and gateways.
Without DHCP, administrators would have to manually configure static IP settings on every host workstation.
2
Identify the service required for local hostname-to-IP resolution.
The DNS server role manages resource records that map domain names and hostnames to IP addresses.
DNS allows users and applications to communicate with local resources using friendly names rather than memorizing IP addresses.

Anahtar Kavram

Core Network Host Services: DHCP for dynamic IP assignment and DNS for hostname resolution.
Tahmini Süre:1m 30s
Soru 2675Soru

An IT technician is hardening a workstation located in a shared medical clinic treatment room. To mitigate the risk of unauthorized access when clinical staff temporarily step away from the active session, the technician must ensure the desktop automatically secures itself after three minutes of inactivity and requires user authentication to resume. Which of the following configuration settings directly accomplishes this security objective?

Cevabı ve açıklamayı göster

Cevap: Screen saver timeout set to 3 minutes with the requirement to display the logon screen on resume enabled

Cevap

Screen saver timeout set to 3 minutes with the requirement to display the logon screen on resume enabled
Enabling a screen saver timeout with password protection on resume automatically locks an unattended desktop after a specified duration of inactivity. This requires the user to re-enter credentials before granting access, effectively preventing unauthorized physical access to sensitive data when staff step away.

Adım Adım Çözüm

1
Identify the primary threat presented in the scenario
The risk is an unattended, active user session remaining accessible to unauthorized individuals when staff step away.
Hardening workstation policies requires mitigating unauthorized physical access during staff absence.
2
Evaluate operating system controls for automated inactivity locking
Configuring a short screen saver timeout paired with requiring logon/password on resume forces the OS to lock the desktop session upon reaching the inactivity threshold.
This specific setting directly secures an active session without requiring manual logoff.
3
Distinguish from secondary workstation security settings
Account lockout policies restrict password guessing attacks, UAC restricts unauthorized privilege escalation, and disabling Guest accounts restricts default login access.
None of these secondary controls automatically lock an existing active idle session.

Anahtar Kavram

Workstation Hardening via Screen Saver Lockout Policies
Tahmini Süre:1m 15s
Soru 2676Soru

An IT technician is provisioning corporate mobile tablets for field delivery drivers. The organization requires the tablets to lock down user interaction so drivers can only run a proprietary navigation app, while completely blocking access to device settings, web browsers, and third-party app installations. Which Mobile Device Management (MDM) configuration should the technician apply?

Cevabı ve açıklamayı göster

Cevap: Enable Single-App Kiosk Mode combined with mandatory application whitelisting

Cevap

Enable Single-App Kiosk Mode combined with mandatory application whitelisting
Single-App Kiosk mode pins the mobile operating system to a single predefined app, disabling access to the home screen, status bar, device settings, and other applications. Application whitelisting ensures that only explicitly approved applications are permitted to execute on the platform.

Adım Adım Çözüm

1
Identify the operational requirement for dedicated device deployment.
The requirement mandates that the mobile device run exclusively one application while preventing OS navigation, settings modifications, or installing unapproved apps.
Dedicated single-purpose hardware requires full system lock-down controls.
2
Evaluate MDM policy types designed for restricted single-purpose use.
Single-App Kiosk mode locks the OS interface directly into the designated application, while app whitelisting prevents any unauthorized executables from running.
Kiosk mode combined with whitelisting directly addresses the requirement to restrict device access exclusively to the specified application.

Anahtar Kavram

Mobile Device Kiosk Mode and Application Whitelisting
Tahmini Süre:1m 15s
Soru 2677Soru

During a scheduled maintenance window, a system administrator updates the storage controller drivers on a Windows 10 workstation. Upon rebooting, the system fails to start and displays a Stop Error (BSOD) indicating CRITICAL_PROCESS_DIED, followed by an automatic reboot into the Windows Recovery Environment (WinRE). The administrator suspects that the newly installed third-party storage driver is corrupt and causing a kernel crash during early boot initialization. Which command should the administrator execute from the WinRE command prompt to list all third-party drivers installed on the offline Windows OS partition so the problematic driver package can be identified?

Cevabı ve açıklamayı göster

Cevap: dism /image:C:\ /get-drivers

Cevap

The command dism /image:C:\ /get-drivers must be executed to enumerate third-party driver packages on an offline Windows installation within WinRE.
The correct option is the command dism /image:C:\ /get-drivers. DISM is the standard Windows command-line tool capable of targeting offline operating system installations using the /image switch. When combined with /get-drivers, it inspects the offline driver store and outputs details for all installed third-party drivers (listed as oem#.inf files), enabling the administrator to identify the corrupt driver for removal.

Adım Adım Çözüm

1
Identify the environment and requirements
The system cannot boot into standard Windows due to a corrupt driver causing a early boot Stop Error (BSOD), requiring offline servicing from the Windows Recovery Environment (WinRE).
WinRE loads a minimal PE environment from which offline system image modification is required.
2
Select the appropriate offline image servicing tool
DISM (Deployment Image Servicing and Management) is the native Windows utility designed to service offline Windows images.
Tools like PnPUtil and driverquery operate only within an active online Windows OS instance.
3
Apply the correct DISM switches for offline driver enumeration
Executing dism /image:C:\ /get-drivers targets the offline C: system directory and enumerates third-party driver publish names (e.g., oem#.inf).
This allows the technician to locate the exact driver INF file name needed for subsequent removal via dism /image:C:\ /remove-driver.

Anahtar Kavram

Offline Driver Servicing in WinRE using DISM

Alternatif Yöntem

Alternatively, the administrator could boot into Safe Mode if reachable, or use DISM to remove the driver package directly once the published driver name (oem#.inf) is identified.
Tahmini Süre:2m 0s
Soru 2678Soru

A systems technician at a municipal water treatment facility has just finished isolating a Windows workstation infected with a spyware keylogger, disabling System Restore, updating the antivirus definitions in Safe Mode, and successfully removing the malicious software. Which of the following actions should the technician perform NEXT according to the standard CompTIA malware remediation process?

Cevabı ve açıklamayı göster

Cevap: Schedule automatic anti-malware updates and routine system scans

Cevap

The technician should schedule automatic anti-malware updates and routine system scans.
The CompTIA 7-step malware remediation process follows a specific order: 1. Identify malware symptoms, 2. Quarantine infected systems, 3. Disable System Restore, 4. Remediate infected systems (update anti-malware signatures, scan, and remove), 5. Schedule updates and initiate scans, 6. Enable System Restore and create a restore point, and 7. Educate the end user. Since remediation (Step 4) has just concluded, the correct next action is Step 5: scheduling updates and scans.

Adım Adım Çözüm

1
Identify the current step in the CompTIA 7-step malware remediation process.
The technician has completed Step 1 (Identify), Step 2 (Quarantine), Step 3 (Disable System Restore), and Step 4 (Remediate: update anti-malware and scan/remove).
Tracking current progress ensures strict adherence to standard operating procedures.
2
Determine the next sequential step in the process.
Step 5 is 'Schedule updates and initiate scans'.
Scheduling updates and scans ensures the system remains protected against future infections before finalizing system configuration.
3
Select the option that matches Step 5.
Scheduling automatic anti-malware updates and routine system scans.
This directly fulfills Step 5 of the 7-step remediation workflow.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process
Soru 2679Soru

A user reports that a custom inventory management application freezes and stops responding whenever large database reports are executed. Place the troubleshooting steps in the correct order to identify and resolve the blocking process causing the application freeze.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct troubleshooting sequence is: 1) Open Task Manager using Ctrl + Shift + Esc to view resource usage, 2) Launch Resource Monitor from the Performance tab, 3) Right-click the non-responsive process and select Analyze Wait Chain, and 4) Terminate the specific blocking process identified in the wait chain tree.
The proper administrative workflow begins with establishing basic process visibility in Task Manager, advancing to Resource Monitor for detailed thread inspection, executing Analyze Wait Chain to discover dependent deadlocks, and finally terminating the blocking process to restore application functionality.

Adım Adım Çözüm

1
Press Ctrl + Shift + Esc to open Task Manager.
Task Manager opens, displaying basic system utilization metrics and identifying which processes are listed as 'Not Responding'.
Establishing initial diagnostic visibility allows the technician to confirm system state before performing deeper analysis.
2
Open Resource Monitor from the Performance tab.
Resource Monitor opens, granting access to process-level thread queues, disk activity, and wait chain analysis.
Task Manager shows summary data, but Resource Monitor provides the advanced thread analysis needed to diagnose process deadlocks.
3
Right-click the hanging process under the CPU tab and click Analyze Wait Chain.
A window opens displaying the process thread tree, highlighting any subordinate or sibling process holding locked resources.
Wait Chain Analysis pinpoints the precise secondary thread or process causing the primary application to freeze.
4
Select the blocking process PID shown in the wait tree and end the process.
The blocking thread releases locked handles, allowing the primary application to resume execution or close cleanly.
Targeting the specific blocking dependency resolves the deadlock without abruptly terminating un-saved application data unless necessary.

Anahtar Kavram

Process Wait Chain Analysis in Windows Resource Monitor
Soru 2680Soru

A security administrator is updating Mobile Device Management (MDM) policy profiles for mobile devices connecting to corporate data under a Bring Your Own Device (BYOD) initiative. The security strategy requires isolating corporate data from personal applications to prevent data leakage and prohibiting users from installing unverified applications from unofficial app stores. Which TWO of the following security controls should the administrator implement to meet these requirements? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Enforce app containerization with data loss prevention (DLP) copy-paste restrictions; Restrict app installation sources by disabling app sideloading on all enrolled devices

Cevap

The correct controls are enforcing app containerization with data loss prevention restrictions and disabling application sideloading on all enrolled mobile devices.
The correct options implement containerization (which separates enterprise app data from personal apps via encryption and DLP rules) and disable application sideloading (which stops the installation of third-party apps from unverified sources).

Adım Adım Çözüm

1
Analyze the requirement for isolating corporate data from personal applications on BYOD devices.
Identify that containerization separates personal and enterprise storage spaces, preventing unauthorized data sharing.
Containerization creates a secure encrypted partition managed by MDM.
2
Analyze the requirement to block installations from unverified app stores.
Identify that disabling application sideloading enforces software installation strictly from trusted software repositories.
Sideloading bypasses platform security vetting and increases malware risks.

Anahtar Kavram

Mobile Device Management (MDM) BYOD controls including containerization and restricting application sources (sideloading restrictions).
ÖncekiSayfa 134 / 178Sonraki
Tüm alıştırma soruları — CompTIA A+ (Core 1 & Core 2) | Examkin