Tüm alıştırma soruları

3551 soru

Soru 61Soru

A field technician is troubleshooting a conference room ceiling-mounted projector. The projector displays a sharp, properly aligned image when powered on, but after approximately 10 to 15 minutes of continuous operation, it abruptly shuts off and illuminates a solid red thermal status LED on the chassis. After cooling down for 20 minutes, the unit powers back on normally. Which of the following is the MOST likely cause of this issue?

Cevabı ve açıklamayı göster

Cevap: Clogged air intake filters causing internal heat buildup and safety cutoff

Cevap

Clogged air intake filters causing internal heat buildup and safety cutoff
High-intensity projector bulbs produce substantial operating heat. Cooling fans draw room air across internal components through removable air filters. When these filters become blocked with dust, airflow drops significantly, causing heat to rapidly accumulate until an internal thermal sensor trips an automatic safety shutdown to protect the bulb and optics.

Adım Adım Çözüm

1
Analyze reported symptom and hardware behavior
The projector functions normally for 10-15 minutes before shutting off with a red thermal indicator light, then recovers after cooling down.
Delayed shutdown combined with a thermal status LED confirms the failure is triggered by internal overheating.
2
Identify the cooling failure mechanism
Projector lamps generate extreme heat and rely on unobstructed airflow through dust filters and intake vents to dissipate thermal energy.
When dust accumulates on the intake filters, airflow is restricted, causing internal operating temperatures to exceed safety thresholds and engage automatic thermal shutdown.
3
Rule out alternative distractor causes
Software display drivers affect signal processing on the host PC, video cable bandwidth affects resolution/refresh rate capabilities, and backlight inverters belong to legacy CCFL LCD displays.
None of the alternative causes account for physical projector temperature warnings or temporary recovery after thermal dissipation.

Anahtar Kavram

Projector Thermal Protection and Maintenance
Soru 62Soru

A technician is diagnosing several video display and projector issues across a corporate office. Match each observed symptom or scenario with its primary hardware or configuration root cause.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

An OLED laptop display exhibits faint, persistent outlines of a static application toolbar even after switching applications.
A ceiling-mounted projector powers off unexpectedly after 15 minutes of operation, accompanied by a solid warning LED.
A desktop monitor displays flickering horizontal line artifacts that are visible both on the physical screen and in software screenshots.
A newly installed projector displays an image that is visibly wider at the top of the screen than at the bottom.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

The correct pairings connect each display symptom directly to its underlying cause: 1) OLED static outlines match image burn-in on OLED materials. 2) Projector shutdown after 15 minutes matches thermal shutdown from clogged airflow/filters. 3) Line artifacts captured in screenshots match GPU/VRAM hardware rendering corruption. 4) Trapezoidal wide-top image matches keystone distortion from non-perpendicular alignment.
Each display anomaly corresponds to a specific hardware characteristic: OLED displays suffer burn-in from static UI elements; projectors execute thermal shutdowns when thermal vents or dust filters restrict airflow; GPU/VRAM hardware faults generate rendering artifacts recorded by screenshot tools; and non-perpendicular optical projection causes keystone trapezoidal distortion.

Adım Adım Çözüm

1
Analyze the OLED screen ghosting symptom.
Identified as OLED image burn-in resulting from continuous exposure to static user interface elements.
OLED pixels degrade at different rates when static elements remain on screen for extended periods.
2
Analyze the projector timed shutdown symptom.
Identified as a thermal safety shutdown induced by restricted cooling path/filters.
Projectors contain thermal sensors that force power-off to protect expensive lamps and optics when internal temperatures exceed safety thresholds.
3
Evaluate the visual artifact symptom present in software screenshots.
Identified as video card GPU or VRAM corruption.
If artifacts appear in a software screenshot (Print Screen / OS grab), the rendering error exists upstream in GPU memory before video signal output.
4
Evaluate the non-rectangular trapezoidal projector image shape.
Identified as keystone distortion.
Angling the projector beam non-perpendicularly against a flat surface stretches the top or bottom edge of the projected image.

Anahtar Kavram

Troubleshooting Video, Display, and Projector Physical Symptoms
Soru 63Soru

A desktop technician has finished scanning and removing a spyware infection from a Windows workstation, updated the operating system and anti-malware signature files, and configured scheduled recurring scans. According to the CompTIA 7-step malware remediation process, which of the following actions should the technician perform NEXT?

Cevabı ve açıklamayı göster

Cevap: Re-enable System Restore and create a new restore point.

Cevap

Re-enable System Restore and create a new restore point.
The standard CompTIA 7-step malware remediation process follows this exact order: 1. Identify malware symptoms, 2. Quarantine infected systems, 3. Disable System Restore, 4. Remediate infected systems (update anti-malware and scan/remove), 5. Schedule scans and run updates, 6. Enable System Restore and create a restore point, 7. Educate end user. Because the scenario states that infection removal, signature updating, and scan scheduling have already occurred, the immediate next action is to re-enable System Restore and create a new restore point.

Adım Adım Çözüm

1
Identify the completed steps from the scenario against the CompTIA 7-step malware remediation process.
Steps 1 through 5 (Identify, Quarantine, Disable System Restore, Remediate/Scan, and Schedule Scans/Updates) are completed.
Determining which steps are already done establishes where the technician currently is in the remediation workflow.
2
Determine Step 6 of the CompTIA 7-step remediation framework.
Step 6 requires re-enabling System Restore and creating a new restore point.
Once the system is verified clean and ongoing prevention scans are scheduled, establishing a known-good recovery point restores baseline protection.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process - Step 6 (Enable System Restore and Create a Restore Point)
Soru 64Soru

A security technician at a defense contractor is investigating a multi-stage security incident reported across the corporate facility. Physical access logs and security footage show an unknown individual wearing a fake delivery uniform closely following an authorized employee through a badge-restricted turnstile without scanning an access card. Later that day, several senior lead engineers received customized emails containing authentic project reference numbers and names of their team members, requesting that they click an external link to verify their corporate credentials. Which of the following social engineering threat types were directly executed during this incident? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Tailgating; Spear phishing

Cevap

The attack involved Tailgating (unauthorized physical entry by following an employee) and Spear Phishing (highly customized email targeting specific engineers).
The scenario describes two distinct threat vectors: physical entry achieved by closely following an authorized badged user through a security turnstile (Tailgating), and an electronic attack utilizing customized internal project references sent to specific senior staff members to harvest credentials (Spear Phishing).

Adım Adım Çözüm

1
Analyze the physical access breach described in the scenario.
The intruder wearing a delivery uniform closely followed a badged employee through a restricted turnstile without presenting credentials.
This physical social engineering technique of entering restricted areas behind authorized personnel is defined as tailgating.
2
Analyze the digital attack vectors presented in the incident report.
Selected senior lead engineers received tailored emails with internal project names and coworker information designed to steal credentials.
Targeted, customized electronic messages directed at specific key individuals inside an organization represent spear phishing rather than broad phishing.
3
Differentiate and eliminate non-matching social engineering attack types.
Vishing requires phone interaction, dumpster diving requires searching trash receptacles, and shoulder surfing requires direct visual monitoring of screens.
None of these secondary vectors were indicated in the security footage or email log evidence.

Anahtar Kavram

Identifying Physical and Digital Social Engineering Vectors
Tahmini Süre:2m 0s
Soru 65Soru

Match each macOS system feature or Linux/macOS command-line utility to its primary administrative function.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

journalctl
Keychain Access
tar
Console

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

journalctl pairs with querying systemd log records; Keychain Access pairs with native macOS password and credential management; tar pairs with aggregating files into an archive; Console pairs with inspecting real-time macOS system diagnostic logs and crash reports.
Each item accurately pairs the administrative tool with its OS-specific function: journalctl accesses systemd binary logs in Linux; Keychain Access securely stores keys and credentials in macOS; tar creates file archives in Linux and macOS; and Console streams real-time logs and diagnostic reports in macOS.

Adım Adım Çözüm

1
Identify the primary function of Linux system logging command-line utilities.
journalctl is recognized as the utility used to query and view systemd journal logs on modern Linux distributions.
Linux systems using systemd rely on journalctl for log viewing rather than reading raw log files directly.
2
Identify macOS security credential management tools.
Keychain Access is identified as the native application responsible for storing saved network passwords, certificates, and keys.
macOS uses Keychain Access to provide centralized, encrypted credential storage.
3
Differentiate file archiving commands from log or monitoring tools.
tar is identified as the tool for bundling multiple files and directories into an archive file.
tar stands for tape archive and is used extensively across UNIX-like systems for backup and file bundling.
4
Distinguish between macOS system log utilities.
Console is matched to real-time macOS diagnostic log and crash report monitoring.
Console provides a graphical environment to stream and filter macOS system events and log entries.

Anahtar Kavram

macOS and Linux System Administration Tools and Logging Features
Soru 66Soru

An IT support specialist is responding to a reported malware infection on a company workstation. Arrange the following actions in the correct sequence according to the standard CompTIA malware removal process, starting with the earliest step and ending with the final step.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence follows the CompTIA 7-step remediation process: 1. Disconnect the infected workstation from the network (Quarantine), 2. Turn off System Restore (Disable System Restore), 3. Update anti-malware definitions and perform a thorough scan (Remediate), 4. Re-enable System Restore and create a clean baseline restore point (Enable System Restore), and 5. Conduct security awareness training (Educate the user).
The standard CompTIA 7-step malware removal workflow mandates the sequence: Identify -> Quarantine -> Disable System Restore -> Remediate (Update & Scan) -> Schedule Updates & Scan -> Enable System Restore & Create Restore Point -> Educate End User. Isolating the system comes first to contain the threat. Disabling System Restore removes corrupted backups. Updating definitions and scanning removes the threat. Re-enabling System Restore creates a verified safe baseline. Finally, user education prevents recurrence.

Adım Adım Çözüm

1
Isolate the infected endpoint from the network infrastructure.
The machine is quarantined to prevent lateral movement of the malware.
Quarantining the infected system immediately follows identifying the malware symptoms.
2
Disable the Windows System Restore feature.
All existing restore points (which may contain malware copies) are deleted.
Disabling System Restore prevents malware from preserving itself in restore archives.
3
Update malware signatures and run remediation tools.
The active malware infection is detected and eradicated.
Remediation requires updated signatures and scanning, typically performed in Safe Mode.
4
Turn System Restore back on and create a new restore point.
System Protection is active again with a known-good clean state image.
System Restore should only be re-enabled after verifying the system is completely clean.
5
Provide end-user training on safe computing practices.
The user is educated on recognizing phishing, rogue downloads, and social engineering.
Educating the user is the final step of the malware removal framework.

Anahtar Kavram

CompTIA 7-Step Malware Removal Process Order
Soru 67Soru

A system administrator is configuring security baselines on standalone Windows 11 Pro workstations located in a shared laboratory environment. To enforce strict access controls and prevent standard domain users from triggering administrative privilege requests or running unauthorized installers, the administrator opens the Local Security Policy snap-in (secpol.msc). Which TWO User Account Control (UAC) policy settings should the administrator configure under Security Options? Select TWO.

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Set 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests'; Set 'User Account Control: Detect application installations and prompt for elevation' to 'Enabled'

Cevap

The administrator should configure 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' and set 'User Account Control: Detect application installations and prompt for elevation' to 'Enabled'.
Configuring 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' prevents standard users from receiving credential prompts during elevation attempts. Setting 'User Account Control: Detect application installations and prompt for elevation' to 'Enabled' ensures software installation routines trigger UAC evaluation.

Adım Adım Çözüm

1
Identify the proper snap-in for configuring User Account Control security baselines
Local Security Policy (secpol.msc) under Security Options houses granular UAC policy settings.
System-wide UAC elevation and detection policies are managed via local security options.
2
Select the policy setting that suppresses elevation prompts for standard accounts
Setting 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' prevents standard users from seeing credential prompts.
This automatically blocks privilege elevation attempts by non-administrative users.
3
Select the policy setting that monitors software installer executions
Enabling 'User Account Control: Detect application installations and prompt for elevation' causes Windows to detect setup programs and require elevation.
This prevents unauthorized applications from making silent or unapproved system modifications.

Anahtar Kavram

Windows User Account Control (UAC) Security Options in Local Security Policy (secpol.msc)
Soru 68Soru

An IT security technician is finalizing a data destruction workflow for a decommissioned enterprise storage array that contains both magnetic Hard Disk Drives (HDDs) and Solid-State Drives (SSDs). The technician plans to pass all drives through a powerful magnetic degausser as the primary sanitization step before sending the hardware off-site for physical shredding. Which of the following identifies the most critical security flaw in this proposed workflow?

Cevabı ve açıklamayı göster

Cevap: Degaussing is ineffective for solid-state drives because flash memory does not store data magnetically, leaving the data on the SSDs fully intact.

Cevap

Degaussing is ineffective for solid-state drives because flash memory does not store data magnetically, leaving the data on the SSDs fully intact.
Degaussing exposes media to a powerful magnetic field to eliminate stored magnetic patterns. While highly effective for magnetic hard disk drives (HDDs) and magnetic tapes, it does not affect semiconductor flash memory used in solid-state drives (SSDs). Therefore, applying a degausser to SSDs leaves the stored data completely intact.

Adım Adım Çözüm

1
Analyze the underlying storage technology of the drives in the scenario.
The array contains magnetic HDDs (platter-based magnetic domains) and SSDs (NAND flash semiconductor memory cells).
Sanitization protocols must align with the physical storage mechanism of each media type.
2
Evaluate the operational mechanism of degaussing.
Degaussing exposes drives to high-density magnetic fields to neutralize magnetic alignment.
This method relies on changing the polarity of ferromagnetic material.
3
Identify the impact on non-magnetic solid-state media.
Degaussing has zero effect on electrical charges trapped in NAND flash transistors, leaving all SSD data completely intact.
Semiconductor flash storage does not utilize magnetic domains to record data.

Anahtar Kavram

Selecting media-appropriate data destruction techniques (Degaussing for magnetic media vs. Cryptographic Erase/Purge/Physical Shredding for solid-state media)
Soru 69Soru

A systems administrator is configuring remote support capabilities on standalone Windows 11 Pro workstations. During remote management sessions, the helpdesk technician notices that whenever an action requires elevated administrative privileges, the remote screen turns black and becomes non-responsive, preventing the technician from seeing or interacting with the elevation prompt. Local security policy mandates that User Account Control (UAC) elevation prompts must remain active for all administrative tasks. Which of the following Local Security Policy settings should the administrator modify to resolve the remote screen blackout issue while maintaining elevation prompts?

Cevabı ve açıklamayı göster

Cevap: Disable 'User Account Control: Switch to the secure desktop when prompting for elevation'.

Cevap

Disable 'User Account Control: Switch to the secure desktop when prompting for elevation'.
When User Account Control prompts for administrative elevation, Windows by default dims the screen and transfers focus to the Secure Desktop—an isolated context accessible only by trusted system components. Standard remote support and screen-sharing utilities often lack the necessary privileges to render or accept input on the Secure Desktop, resulting in a blank or frozen remote view. Disabling 'User Account Control: Switch to the secure desktop when prompting for elevation' causes prompts to render on the active user's desktop, enabling remote technicians to view and respond to UAC prompts while keeping prompt verification fully active.

Adım Adım Çözüm

1
Diagnose the cause of the screen blackout during remote UAC elevation requests.
By default, Windows switches to the Secure Desktop (Winlogon desktop) to present UAC prompts. Most remote support software without system-level UIAccess cannot capture or send input to the Secure Desktop, causing the remote display to go black.
The Secure Desktop protects elevation prompts from malware screen-scraping and synthetic input.
2
Evaluate administrative security constraints.
UAC elevation prompts must remain enabled for administrator accounts.
Silently elevating administrative requests violates organizational compliance rules.
3
Reconfigure the Local Security Policy setting.
Disabling 'User Account Control: Switch to the secure desktop when prompting for elevation' presents UAC prompts on the interactive user desktop rather than the isolated Secure Desktop.
This allows remote desktop software to view and process UAC prompts without disabling elevation security.

Anahtar Kavram

User Account Control Secure Desktop isolation and Local Security Policy configuration
Soru 70Soru

A Windows 11 desktop computer is experiencing persistent connectivity issues following a router migration. A help desk technician needs to purge the local DNS resolver cache to remove stale IP address mappings and reset the IPv4 protocol stack to its default state to resolve protocol stack corruption. Which of the following commands should the technician execute on the client machine? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: ipconfig /flushdns; netsh int ip reset

Cevap

The technician must execute `ipconfig /flushdns` to purge stale host name records from the local resolver cache and `netsh int ip reset` to restore the TCP/IP protocol stack to its clean default configuration.
Executing `ipconfig /flushdns` flushes obsolete address entries stored in the local client cache. Executing `netsh int ip reset` resets the TCP/IP interface stack by overwriting registry keys controlling network protocols, resolving protocol layer corruption.

Adım Adım Çözüm

1
Identify the command required to clear cached local DNS resolver entries.
The `ipconfig /flushdns` command empties the local DNS cache so the client performs fresh DNS queries.
Outdated host-to-IP mappings cause routing failure to local or remote host names after router reconfigurations.
2
Identify the command required to reset the TCP/IP stack configuration.
Executing `netsh int ip reset` rewrites registry keys controlling TCP/IP settings to defaults.
Protocol stack corruption prevents stable socket operations, requiring a reset of the network stack.

Anahtar Kavram

Windows Network Command-Line Diagnostics and Repair
Soru 71Soru

A field technician is diagnosing various display and projector issues across an enterprise network. Which underlying hardware failure or administrative adjustment correctly matches each observed symptom?

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

A laptop screen remains completely dark upon boot, but faint desktop icon outlines are visible when a high-intensity flashlight is shined directly on the panel.
A CAD workstation monitor displays dynamic checkerboard patterns and distorted line geometry specifically during heavy 3D graphic processing.
A newly installed conference room projector displays an image that is significantly wider at the top of the wall screen than at the bottom.
A desktop LCD panel constantly displays a persistent single red pixel that never changes color regardless of the background image.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

The symptoms map to their corresponding root causes as follows: faint image under flashlight correlates with backlight/inverter failure; rendering artifacts during 3D workload correlate with failing VRAM/GPU hardware; trapezoidal projected image correlates with keystone correction requirements; and a permanently lit red pixel correlates with a stuck transistor defect.
Each symptom aligns directly with its underlying hardware condition: a faint image under flashlight indicates failure of the backlight illumination components; 3D rendering artifacts indicate memory or processing failure on the GPU adapter; trapezoidal projection shapes indicate an angled projection path requiring keystone correction; and a constantly lit single color pixel indicates an individual subpixel transistor stuck in an active state.

Adım Adım Çözüm

1
Diagnose the unlit LCD panel displaying faint graphics
Confirm screen content is rendered but lacks internal illumination
Using an external light source validates that the display adapter and panel logic operate properly while the backlight or inverter circuit has failed.
2
Diagnose screen artifacts appearing under graphical load
Isolate the issue to dedicated graphics hardware elements
Corrupted frame buffer data caused by failing video RAM or an overheating GPU chip produces visual anomalies such as lines and checkerboards during 3D calculations.
3
Diagnose trapezoidal projector output distortion
Identify geometric misalignment between lens throw angle and screen
When top and bottom light paths differ in distance to the screen surface, keystone adjustment is applied to compensate digitally for the angle.
4
Differentiate stuck pixels from dead pixels
Identify transistor operational state within the LCD matrix
A continuously energized transistor produces a constant colored light output (stuck pixel), whereas a non-functioning transistor produces no light (dead pixel).

Anahtar Kavram

Display and Projector Symptom Isolation and Root Cause Analysis
Soru 72Soru

An enterprise systems administrator is decommissioning a high-security server room containing legacy magnetic hard disk drives (HDDs) holding regulated customer financial records. Company policy mandates a strict sanitization and disposal workflow adhering to NIST SP 800-88 guidelines and complete chain-of-custody preservation. Place the technician's disposition actions in the correct chronological order from start to finish.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct chronological sequence begins with recording drive serial numbers and securing them in tamper-evident containers, followed by degaussing the magnetic media, mechanically shredding the drives, inspecting shredded fragments for compliance, and finally obtaining a signed Certificate of Destruction to update inventory records.
Proper security lifecycle management requires maintaining strict chain of custody from beginning to end. Serial numbers must first be logged and packaged securely. Magnetic drives are then degaussed to purge data prior to mechanical destruction. Physical shredding follows degaussing to ensure hardware cannot be reconstructed. The shredded residue is visually verified to meet particle size standards, and finally, a signed Certificate of Destruction is executed to update organizational records.

Adım Adım Çözüm

1
Establish Chain of Custody & Document Assets
Drive serial numbers are recorded in the compliance tracking log and sealed in tamper-evident packaging prior to movement.
Chain-of-custody tracking must initiate before media leaves its secure operational enclosure to prevent unauthorized loss or theft.
2
Execute Magnetic Sanitization (Degaussing)
The internal magnetic fields on the HDD platters and factory timing tracks are permanently disrupted.
Purging data via degaussing renders data unrecoverable while the drive remains physically intact, ensuring data is safe before destruction machinery handling.
3
Execute Physical Destruction (Mechanical Shredding)
The hard drives are shredded into physical metal debris and particulate matter.
Physical destruction ensures total physical impossibility of drive reassembly or head alignment.
4
Perform Destruction Verification
The physical waste output is verified against compliance particle size specifications.
Verification confirms that the physical destruction step met security standards before issuing formal disposition compliance paperwork.
5
Finalize Compliance Documentation
A Certificate of Destruction is generated, signed, attached to serial number logs, and marked closed in asset management.
Legal and regulatory compliance requires formal documentation signed post-destruction to finalize hardware decommission lifecycle.

Anahtar Kavram

Enterprise Media Sanitization Lifecycle & Chain of Custody Protocol
Soru 73Soru

An IT technician is resolving a ticket regarding a network multifunction device (MFD) deployed in a corporate branch office. Office employees report that while standard document printing and local photocopying work properly, attempting to send scanned documents using the MFD's 'Scan to Email' feature fails with a destination network error. The network administrator confirms that the organization recently updated its mail security policy to enforce SMTP authentication over TLS on port 587. Which of the following is the most likely cause of the scan feature failure?

Cevabı ve açıklamayı göster

Cevap: The MFD's embedded web server has outdated outgoing mail settings and lacks updated SMTP server authentication credentials.

Cevap

The MFD's embedded web server has outdated outgoing mail settings and lacks updated SMTP server authentication credentials.
Multifunction devices (MFDs) utilize Simple Mail Transfer Protocol (SMTP) to transmit scanned documents to recipient mailboxes. When a corporate mail server upgrades its security policy to require encrypted authentication over non-standard or secure ports (such as TCP 587), the MFD's outgoing SMTP configuration must be updated via its Embedded Web Server (EWS) to supply valid authentication credentials and specify the correct port.

Adım Adım Çözüm

1
Analyze the reported symptoms and operational context
Network printing and local photocopying function normally, confirming that physical connectivity, local network communications, and print engine hardware are operational.
Isolates the failure specifically to the outbound application service layer ('Scan to Email' / SMTP).
2
Correlate recent environment changes with the destination network error
The mail server was updated to enforce authentication and TLS port 587 for outbound email.
Multifunction devices act as SMTP clients when sending scanned attachments via email and require matching server authentication credentials and port configurations.
3
Determine the necessary administrative resolution
Access the MFD's Embedded Web Server (EWS) to update the SMTP configuration settings with valid credentials, TLS encryption enabled, and target port 587.
Aligns the MFD client configuration with the updated mail server security requirements.

Anahtar Kavram

Multifunction Device (MFD) Scan-to-Email Configuration and SMTP Authentication
Soru 74Soru

A system administrator is hardening domain-joined Windows 11 Pro workstations to adhere to a strict corporate security baseline. Under this baseline, standard domain users must be completely prevented from initiating elevation attempts—if an unprivileged account triggers a process requiring administrative credentials, the operating system must immediately reject the request without presenting a credential prompt. Furthermore, administrators logged in under Admin Approval Mode must explicitly re-enter their domain credentials on the Secure Desktop whenever an application requests elevated privileges. Which combination of Local Security Policy (secpol.msc) settings under User Account Control will correctly enforce this baseline?

Cevabı ve açıklamayı göster

Cevap: Configure 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests', and set 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' to 'Prompt for credentials on the secure desktop'.

Cevap

Configure 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests', and set 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' to 'Prompt for credentials on the secure desktop'.
In Windows Local Security Policy (secpol.msc), administrators can independently configure UAC prompt behaviors. Setting 'Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' immediately returns an access denied message without showing a credential prompt. Setting 'Behavior of the elevation prompt for administrators in Admin Approval Mode' to 'Prompt for credentials on the secure desktop' ensures that administrators must re-enter credentials on a dimmed, isolated desktop environment protected against spoofing.

Adım Adım Çözüm

1
Identify the administrative tool used for granular UAC policy management.
Local Security Policy (secpol.msc) under Security Settings -> Local Policies -> Security Options contains the specific UAC policy behaviors.
GUI sliders in Control Panel only offer macro-level UAC settings, whereas secpol.msc provides specific policy controls for standard vs administrative elevation behavior.
2
Select the policy controlling standard user elevation attempts.
Setting 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' prevents standard users from seeing credential prompts and denies elevation instantly.
This satisfies the baseline requirement to block unprivileged accounts from attempting privilege escalation.
3
Select the policy controlling administrator elevation verification.
Setting 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' to 'Prompt for credentials on the secure desktop' forces password re-entry on the isolated Secure Desktop.
This satisfies the requirement that administrators must verify their identity via password prompt on the Secure Desktop prior to elevated application launch.

Anahtar Kavram

Windows Local Security Policy User Account Control Settings
Soru 75Soru

A security administrator is hardening standalone Windows 11 Professional workstations deployed in a public testing center. To adhere to compliance guidelines, standard user accounts must be strictly prohibited from triggering administrator credential prompts upon attempting elevated tasks, and any executable requesting administrative privileges must be verified against a valid digital signature infrastructure before elevation is permitted. Which TWO settings in Local Security Policy (secpol.msc) under Security Options should the administrator configure to meet these requirements? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Set 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests'; Set 'User Account Control: Only elevate executables that are signed and validated' to 'Enabled'

Cevap

The administrator must set 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' and set 'User Account Control: Only elevate executables that are signed and validated' to 'Enabled'.
Configuring 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' suppresses administrator credential prompts for non-admin accounts and rejects the operation. Additionally, enabling 'User Account Control: Only elevate executables that are signed and validated' mandates that any executable requesting administrative privileges must pass PKI cryptographic signature checks prior to execution.

Adım Adım Çözüm

1
Open Local Security Policy console by running 'secpol.msc' on the Windows 11 Professional workstation.
Access to Local Policies -> Security Options is established.
UAC security policies for domain-independent or standalone machines are managed within Security Options.
2
Locate 'User Account Control: Behavior of the elevation prompt for standard users' and select 'Automatically deny elevation requests'.
Standard users will receive an access denied message without any prompt to enter administrator credentials when trying to run elevated tasks.
Fulfills the requirement to prevent standard users from attempting privilege escalation or viewing credential prompts.
3
Locate 'User Account Control: Only elevate executables that are signed and validated' and set it to 'Enabled'.
Windows will enforce Public Key Infrastructure (PKI) signature validation on binary executables requesting administrative access before triggering elevation.
Fulfills the requirement to mandate digital signature verification for elevated software.

Anahtar Kavram

Local Security Policy UAC Security Options
Soru 76Soru

A Windows workstation running an enterprise database utility experiences frequent '(Not Responding)' freezes followed by sudden application crashes during heavy reporting tasks. Task Manager shows moderate CPU (25%) and Memory (40%) utilization, but overall responsiveness drops significantly during file exports. A technician suspects storage subsystem latency is causing the application timeouts and crashes. Which of the following tools and metrics should the technician inspect FIRST to isolate this storage performance bottleneck?

Cevabı ve açıklamayı göster

Cevap: Resource Monitor to evaluate Disk Queue Length and Average Response Time for the specific process.

Cevap

Resource Monitor to evaluate Disk Queue Length and Average Response Time for the specific process.
Evaluating Resource Monitor allows the technician to break down disk performance by individual process. Checking metrics such as Disk Queue Length and Average Response Time directly measures storage latency and I/O saturation, confirming if storage bottlenecks are causing application timeouts.

Adım Adım Çözüm

1
Analyze the symptoms described in the scenario
CPU and Memory utilization are normal, but disk-heavy tasks cause freezes and application crashes due to suspected storage latency.
Identifying the root system component affected helps narrow down the diagnostic tool required.
2
Select the administrative tool designed for real-time process-specific disk I/O analysis
Resource Monitor displays active processes along with real-time disk response times and queue lengths.
High Disk Queue Length (consistently above 2 per disk) and elevated Average Response Time (ms) confirm disk I/O bottlenecks.

Anahtar Kavram

Identifying Storage Performance Bottlenecks with Resource Monitor
Tahmini Süre:1m 15s
Soru 77Soru

A systems administrator is configuring a reference workstation to create a golden master image that will be deployed to dozens of new computers across an enterprise network. Before capturing the OS image, the administrator needs to ensure that hardware-specific information and unique system identifiers are removed and that the image can be captured cleanly without file lock conflicts. Which of the following procedures should the administrator perform to achieve this? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Run the System Preparation tool (sysprep.exe) with the /generalize switch to remove computer-specific details like the Security Identifier (SID).; Boot the reference computer into Windows Preinstallation Environment (WinPE) to run the disk imaging capture utility.

Cevap

To prepare and capture a golden master image for network deployment, the administrator must run `sysprep.exe /generalize` to strip unique system identifiers (SIDs) and boot into a WinPE environment to capture the offline system drive cleanly.
Executing the System Preparation tool (`sysprep.exe`) with the `/generalize` parameter removes system-unique information such as the computer security identifier (SID) and hardware profile details, allowing the OS image to be deployed across diverse hardware configurations. Booting into WinPE places the target system drive in an offline, unmounted state, allowing imaging tools to capture an exact image of the volume without file lock interference from active system processes.

Adım Adım Çözüm

1
Generalize the operating system state
System-specific hardware drivers, SID, and unique identifiers are removed from the Windows installation.
Cloning an operating system without generalizing causes duplicate SIDs and configuration conflicts on the enterprise network.
2
Boot into Windows PE (WinPE)
The host OS volume is brought offline while running a minimal lightweight environment.
Running the image capture utility from WinPE avoids file locking and filesystem state changes that occur when imaging a live OS volume.

Anahtar Kavram

Windows OS Image Generalization and Capture Procedures
Tahmini Süre:1m 30s
Soru 78Soru

An IT support technician is troubleshooting a Windows 10 computer that fails to boot following an improper shutdown. Upon starting, the system displays the error message "The Boot Configuration Data for your PC is missing or contains errors. Error code: 0xc000000f." The technician boots into the Windows Recovery Environment (WinRE) Command Prompt and attempts to repair the boot configuration by running `bootrec /rebuildbcd`. The command identifies the `C:\Windows` installation, but when attempting to add it to the boot list, it fails with the error message "The requested system device cannot be found." Further inspection using `diskpart` reveals that the system drive utilizes GUID Partition Table (GPT) formatting with an unlettered FAT32 EFI System Partition (ESP). Which of the following commands should the technician execute NEXT to successfully repair the boot files?

Cevabı ve açıklamayı göster

Cevap: Use `diskpart` to assign a drive letter to the EFI System Partition, exit `diskpart`, and execute `bcdboot C:\Windows /s S: /f UEFI` to regenerate the BCD store and boot configuration files.

Cevap

Assign a drive letter to the EFI System Partition using diskpart and execute bcdboot to copy fresh boot files to the EFI partition.
When a Windows system configured with UEFI/GPT displays BCD error 0xc000000f and `bootrec /rebuildbcd` fails with 'The requested system device cannot be found', it indicates that WinRE cannot locate or write to the hidden EFI System Partition (ESP). The proper solution is to use `diskpart` to assign a temporary drive letter (such as `S:`) to the volume, exit `diskpart`, and use `bcdboot C:\Windows /s S: /f UEFI` to synthesize fresh boot environment files and recreate the BCD store on the ESP.

Adım Adım Çözüm

1
Identify the system architecture and boot mode.
The disk uses GPT partitioning and UEFI boot architecture, which relies on a hidden FAT32 EFI System Partition (ESP) rather than an MBR boot sector.
Legacy boot recovery tools (`bootrec /fixmbr` or `bootrec /fixboot`) do not work on UEFI systems.
2
Diagnose why `bootrec /rebuildbcd` failed with 'The requested system device cannot be found.'
WinRE cannot locate the hidden EFI System Partition because it does not have a mounted drive letter.
Without an accessible drive letter for the ESP, boot repair utilities cannot write or update BCD store records.
3
Assign a temporary volume letter to the ESP in `diskpart` and run `bcdboot`.
Executing `bcdboot C:\Windows /s S: /f UEFI` creates new BCD environment data and copies required boot files directly from `C:\Windows` into the EFI partition.
The `bcdboot` command is specifically designed to initialize and repair the EFI system partition for UEFI-based Windows installations.

Anahtar Kavram

Troubleshooting UEFI/GPT Windows Boot and BCD Store Corruption
Tahmini Süre:2m 0s
Soru 79Soru

Match each remote access technology or protocol on the left with its corresponding technical characteristic, default port configuration, and operational requirement on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Remote Desktop Protocol (RDP)
Microsoft Remote Assistance (MSRA)
Secure Shell (SSH)
Telnet
Virtual Network Computing (VNC)

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

RDP matches TCP 3389 with host support limited to Windows Pro/Enterprise; MSRA matches TCP 3389 session sharing supported on Home and Pro editions; SSH matches encrypted CLI administration on TCP 22; Telnet matches unencrypted cleartext CLI management on TCP 23; VNC matches cross-platform RFB graphical control on TCP 5900.
Matching each technology correctly requires distinguishing between Windows OS edition constraints (RDP host vs MSRA), default port numbers (TCP 22, 23, 3389, 5900), and protocol security characteristics (SSH encrypted vs Telnet cleartext; RDP/MSRA native vs VNC RFB cross-platform).

Adım Adım Çözüm

1
Analyze Windows graphical remote access protocols and edition constraints.
Differentiate RDP (discrete session, host requires Windows Pro/Enterprise/Education, TCP 3389) from MSRA (shared active session, invitation-based, works on Home editions, TCP 3389).
CompTIA exams strictly evaluate the host capability limitation of Windows Home edition regarding incoming RDP versus user-assisted MSRA.
2
Evaluate command-line interface (CLI) remote access protocols and security postures.
Identify SSH as the secure, encrypted terminal access protocol on TCP port 22, and Telnet as the legacy, unencrypted cleartext terminal protocol on TCP port 23.
Security best practices demand replacing unencrypted protocols like Telnet with encrypted alternatives like SSH.
3
Identify cross-platform graphical remote control standards.
Associate VNC with the Remote Frame Buffer (RFB) protocol and default listening port TCP 5900.
VNC is the standard open-source cross-platform tool for graphical desktop access across mixed operating system environments.

Anahtar Kavram

Remote Access Protocols, Default Listening Ports, Security Profiles, and Windows OS Edition Requirements
Soru 80Soru

Following a component upgrade on a corporate desktop system, the machine powers on and system fans run at maximum speed, but the monitor displays no signal and the keyboard status lights remain unlit. No diagnostic beep codes are emitted from the motherboard speaker. Which of the following initial actions should the technician take to isolate this hardware failure? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Verify that the auxiliary 8-pin EPS12V CPU power connector is securely attached to the motherboard header; Reseat the memory modules and test system boot using a single module in the primary DIMM slot

Cevap

The technician should verify that the auxiliary 8-pin EPS12V CPU power connector is securely connected and reseat the memory modules while testing with a single module in the primary DIMM slot.
When a computer powers on with fans running at high speed but shows no display, no POST beep codes, and unlit keyboard LEDs, the system is failing early in the power-on self-test (POST) process. The most common physical causes are missing CPU power (the auxiliary 8-pin EPS12V connector) or unseated/faulty memory modules. Checking the EPS12V power connection ensures the processor receives adequate voltage to execute BIOS instructions, and isolating/reseating RAM modules rules out memory initialization faults.

Adım Adım Çözüm

1
Check motherboard auxiliary power connections
Ensures the CPU receives proper voltage for core execution and POST initiation
Without auxiliary CPU power (+12V EPS/ATX), the processor cannot execute BIOS/UEFI firmware code.
2
Isolate RAM modules by reseating and testing individually
Determines if an unseated module or faulty RAM stick is halting the POST sequence
Faulty or unseated RAM often prevents video display and system initialization while fans continue to run.

Anahtar Kavram

Pre-POST isolation of power delivery and RAM installation issues
ÖncekiSayfa 4 / 178Sonraki
Tüm alıştırma soruları — CompTIA A+ (Core 1 & Core 2) | Examkin