Tüm alıştırma soruları

3551 soru

Soru 1421Soru

An IT support technician receives multiple tickets from accounting department staff members who report being directed to a suspicious web page when attempting to access the official corporate portal at `https://ledger.company.com`. The technician verifies that users entered the exact, correct web address into their browser address bars. Further investigation reveals that local hosts files are intact, but an attacker successfully compromised local DNS server records to point the corporate portal domain name to an external malicious server. Which of the following threat types best describes this attack?

Cevabı ve açıklamayı göster

Cevap: Pharming

Cevap

Pharming is the correct answer because it involves manipulating DNS records or system host files to silently redirect requests for legitimate web addresses to malicious destinations.
The correct option is pharming because it specifically describes an attack method that alters DNS server records or host configuration files to automatically redirect legitimate web traffic to a rogue site.

Adım Adım Çözüm

1
Analyze the delivery mechanism of the security incident.
Users typed the correct corporate domain URL, but domain resolution directed traffic to an external malicious IP address due to DNS server record manipulation.
Identifying whether the issue stems from user typographical errors, phishing messages, or DNS infrastructure tampering clarifies the exact threat vector.
2
Classify the threat based on CompTIA security definitions.
Traffic redirection achieved via host file alteration or DNS server cache poisoning is classified specifically as pharming.
Pharming attacks exploit network name resolution infrastructure rather than relying on social engineering email links or user typing mistakes.

Anahtar Kavram

Pharming and Infrastructure Manipulation
Soru 1422Soru

A desktop technician needs to update Group Policy settings on a Windows workstation and verify that the computer policies have been successfully applied. Place the following steps in the correct order from first to last to complete this task using the Windows Command Prompt.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence of actions begins with opening an elevated Command Prompt, followed by running `gpupdate /force` to refresh policy settings, executing `gpresult /r` to view the immediate summary of applied policies, and finally running `gpresult /h policy_report.html` to export the comprehensive HTML report.
To update and verify Group Policy settings, a technician must first open an elevated Command Prompt. Next, `gpupdate /force` is run to apply policy changes immediately. Then, `gpresult /r` is executed to review the applied policies in the console summary. Finally, `gpresult /h` is used to export a detailed HTML report for auditing.

Adım Adım Çözüm

1
Launch Command Prompt with elevated administrator rights.
Access to administrator-level command-line system tools is granted.
Modifying system settings and reading computer-level Group Policy objects requires elevated privileges.
2
Execute `gpupdate /force`.
All local and domain policy settings are refreshed immediately.
Forces an immediate update rather than waiting for the standard background refresh interval.
3
Execute `gpresult /r`.
Displays a summary of applied GPOs and security groups directly in the console.
Allows quick interactive verification that newly assigned policies are actively applied.
4
Execute `gpresult /h policy_report.html`.
Creates a structured HTML file containing complete RSoP details.
Provides an exported file artifact for documentation and long-term auditing compliance.

Anahtar Kavram

Group Policy Refresh and RSoP Verification Command-Line Workflow
Soru 1423Soru

Match each administrative or configuration scenario on the left with the corresponding Windows Control Panel utility on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Configuring full-disk encryption, backing up recovery keys, and managing drive volume status.
Enabling High Contrast mode, setting up Sticky Keys, and configuring screen magnifier options.
Modifying local account types, changing user passwords, and adjusting UAC notification levels.
Viewing active network interfaces, configuring IP settings on network adapters, and managing network discovery.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Each administrative task correctly maps to its respective Windows Control Panel applet based on primary functionality: full-disk encryption maps to BitLocker Drive Encryption; accessibility tools map to Ease of Access Center; local credentials and UAC settings map to User Accounts; network interfaces and adapter settings map to Network and Sharing Center.
Each scenario maps directly to the specific Control Panel utility designated for that function in Windows: BitLocker Drive Encryption handles data protection and key backups; Ease of Access Center manages accessibility tools; User Accounts handles local credentials and UAC configuration; Network and Sharing Center handles network interfaces and connection properties.

Adım Adım Çözüm

1
Identify the primary system administrative objective described in each scenario.
Categorize the four scenarios into storage security, accessibility, user account management, and network interface management.
Control Panel applets in Windows are grouped logically by function.
2
Match storage security operations (volume encryption and recovery key management) to BitLocker Drive Encryption.
Pair 1 corresponds to BitLocker Drive Encryption.
BitLocker is the dedicated Windows Control Panel applet for volume-level data protection.
3
Match accessibility tools (High Contrast, Sticky Keys, Magnifier) to Ease of Access Center.
Pair 2 corresponds to Ease of Access Center.
Ease of Access Center serves as the central hub for configuring assistive technology options.
4
Match local user options (account permissions, UAC slider) to User Accounts and network properties (IP setup, adapter configuration) to Network and Sharing Center.
Pair 3 corresponds to User Accounts, and Pair 4 corresponds to Network and Sharing Center.
User Accounts manages local identities and UAC, while Network and Sharing Center manages adapter profiles and connectivity.

Anahtar Kavram

Windows Control Panel Applets and Administrative Utilities
Soru 1424Soru

A user reports that documents printed on a departmental laser printer produce completely blank pages. An IT technician performs a halfway stop test during a print job and observes that a fully formed toner image is present on the photosensitive drum just before the paper enters the transfer zone. Which of the following components is the most likely root cause of this failure?

Cevabı ve açıklamayı göster

Cevap: Transfer roller

Cevap

The transfer roller is the most likely cause because a halfway stop test confirmed that the image was formed on the photosensitive drum, but toner failed to move onto the paper.
The halfway stop test isolates laser printer defects by pausing paper progression mid-cycle. Observing a fully developed toner image on the photosensitive drum confirms that the primary charge roller, laser assembly, and toner cartridge are fully functional. The transfer roller is specifically responsible for charging the paper so that toner transfers from the drum to the paper surface. When the transfer roller fails, toner remains on the drum and paper emerges completely blank.

Adım Adım Çözüm

1
Analyze the halfway stop test results
Toner image is confirmed present on the drum surface prior to transfer.
This proves that image processing, drum charging, laser exposing, and toner developing steps operated normally.
2
Identify the failing step in the electrophotographic process
The failure occurs at the transfer phase.
Toner remains on the drum instead of transferring to the paper passing beneath it.
3
Determine the responsible hardware component
Select the transfer roller.
The transfer roller charges the back of the paper with an opposite potential to pull toner particles off the drum.

Anahtar Kavram

Laser Printing Process and Halfway Stop Test Diagnosis
Tahmini Süre:1m 0s
Soru 1425Soru

An IT technician is preparing a fleet of decommissioned desktop computers containing both magnetic hard disk drives (HDDs) and solid-state drives (SSDs) for transport to an off-site physical destruction facility. Corporate security policy mandates that all storage media must undergo on-site logical sanitization or deactivation to purge all sensitive data prior to leaving the facility. Which TWO of the following procedures should the technician perform to properly sanitize these specific media types on-site? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Executing an ATA or NVMe Secure Erase command on the solid-state drives; Exposing the magnetic hard disk drives to a high-capacity magnetic degausser

Cevap

The technician should execute an ATA or NVMe Secure Erase command on the solid-state drives and apply a high-capacity magnetic degausser to the magnetic hard disk drives.
Proper media disposition requires selecting sanitization techniques matched to the storage media's physical composition. ATA or NVMe Secure Erase sends microcode instructions directly to the drive controller to flush NAND flash memory blocks, making it the correct purging choice for solid-state drives. High-intensity magnetic degaussing neutralizes the magnetic field alignment on platter surfaces, destroying data on magnetic hard disk drives.

Adım Adım Çözüm

1
Identify the media types requiring sanitization
The target devices consist of magnetic media (HDDs) and semiconductor flash media (SSDs).
Different storage technologies require specific sanitization mechanisms.
2
Select appropriate sanitization method for magnetic HDDs
Degaussing destroys magnetic domains on drive platters, purging data on HDDs effectively.
Magnetic fields disrupt physical magnetic storage alignment but have no effect on electronic flash memory.
3
Select appropriate sanitization method for solid-state SSDs
Executing ATA/NVMe Secure Erase applies electrical voltage changes across all NAND flash blocks to flush data.
Flash-based SSDs store charge in micro-transistors rather than magnetic tracks.

Anahtar Kavram

Data sanitization methods must match the physical storage architecture: degaussing applies strictly to magnetic media (HDDs/tapes), whereas solid-state media (SSDs) require firmware-level commands like ATA/NVMe Secure Erase or cryptographic erasure.
Soru 1426Soru

A technician is updating an enterprise data disposition policy for retired equipment. Match each data destruction method to its correct operational application and effect.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Degaussing
ATA Secure Erase
Physical Shredding
Drive Overwriting

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Degaussing corresponds to neutralizing magnetic domains on HDDs/tapes; ATA Secure Erase corresponds to firmware-level purging of SSD storage blocks; Physical Shredding corresponds to mechanical destruction of drive substrates; Drive Overwriting corresponds to replacing logical sectors with zero patterns for drive reuse.
Each disposal technique is properly aligned with its underlying storage technology and operational goals: Degaussing destroys magnetic alignment on magnetic media; ATA Secure Erase triggers onboard controller sanitization for flash media; Physical Shredding provides unrecoverable hardware destruction; and Drive Overwriting cleans magnetic media sectors while preserving hardware functionality for reuse.

Adım Adım Çözüm

1
Identify magnetic-only destruction techniques.
Degaussing requires magnetic media (HDDs, tapes) and renders the drive inoperable by destroying its magnetic alignment and tracks.
Solid-state media does not use magnetic storage, so degaussing has no effect on SSDs.
2
Identify sanitization techniques specific to solid-state storage.
ATA Secure Erase reaches controller-level blocks on SSDs, clearing wear-leveled sectors that standard overwriting tools cannot access.
Standard wiping utilities cannot guarantee complete erasure on SSDs due to wear-leveling algorithms.
3
Differentiate reusable logical sanitization from non-reusable physical destruction.
Drive overwriting permits device reuse, whereas physical shredding destroys hardware completely.
CompTIA standards classify overwriting as sanitization for media reuse, while physical destruction is required for end-of-life disposal under stringent security requirements.

Anahtar Kavram

Data Destruction and Disposal Methods
Soru 1427Soru

A technician is troubleshooting a corporate desktop computer that fails to complete the Power-On Self-Test (POST). When the power button is pressed, the system power LED turns on and cooling fans spin at full speed, but the monitor remains dark and the motherboard emits a continuous series of short beeps. Which of the following initial actions should the technician perform to isolate the issue? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Reseat the existing system memory modules into their respective motherboard slots.; Test the system boot using a single known-good RAM module inserted into one slot at a time.

Cevap

The technician should reseat the existing memory modules into their motherboard slots and test the system using a single known-good RAM module inserted into one slot at a time.
A continuous beep pattern prior to video initialization signifies a POST memory detection failure. Correct troubleshooting requires physically checking memory module contact by reseating them and testing with a single known-good memory module to isolate defective hardware components.

Adım Adım Çözüm

1
Interpret the POST diagnostic symptoms.
Identify that a continuous short beep code during early boot with fans running indicates a failure during memory initialization.
Motherboards use specific audio beep codes during POST to signal hardware failures before display initialization.
2
Formulate logical hardware isolation steps for RAM issues.
Determine that reseating current modules and testing single known-good modules sequentially are standard diagnostic steps for memory issues.
Reseating restores pin contact, while single-module swapping isolates faulty RAM sticks or damaged motherboard slots.

Anahtar Kavram

RAM POST Beep Code Troubleshooting & Physical Isolation
Soru 1428Soru

A technician needs to configure corporate desktops so that they automatically secure themselves when users leave their desks unattended for extended periods. Which of the following workstation hardening best practices should the technician implement?

Cevabı ve açıklamayı göster

Cevap: Configure a screensaver password requirement with a short idle timeout.

Cevap

Configure a screensaver password requirement with a short idle timeout.
Configuring a screensaver password requirement paired with a short idle timeout ensures that when an employee steps away, the workstation locks automatically after the specified time limit, requiring proper authentication to unlock.

Adım Adım Çözüm

1
Identify the primary security requirement.
The requirement is to automatically lock unattended user sessions to prevent unauthorized access.
Physical security best practices require that logged-in workstations lock automatically when left unattended.
2
Evaluate workstation security controls for automatic session locking.
Setting a password-protected screensaver with a low inactivity timeout forces the system to require re-authentication.
This directly mitigates the risk of unauthorized physical access to open user sessions.

Anahtar Kavram

Workstation Hardening - Screen Lock and Idle Timeout Enforcement
Tahmini Süre:45s
Soru 1429Soru

A system administrator is configuring local security policies on Windows 11 Professional workstations to meet corporate compliance standards. The security policy requires that whenever an administrative user performs a task requiring elevated rights, Windows must force the user to re-enter their administrative credentials on the Secure Desktop rather than allowing them to proceed by clicking a simple consent button. Which Local Security Policy policy setting should be modified to enforce this prompt behavior?

Cevabı ve açıklamayı göster

Cevap: User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode

Cevap

The setting 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' controls whether administrators must enter credentials or click consent upon privilege elevation.
The policy setting 'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' allows administrators to specify how administrative accounts respond to elevation requests. Configuring this setting to 'Prompt for credentials on the secure desktop' ensures administrators must type their passwords to elevate privileges rather than relying on standard consent prompts.

Adım Adım Çözüm

1
Identify the goal in Local Security Policy (secpol.msc)
The requirement is to change administrator elevation prompts from simple consent ('Yes/No') to requiring explicit administrative credential re-entry on the Secure Desktop.
Security baselines often mandate credential re-authentication for administrators to prevent session hijacking or unauthorized automated elevation.
2
Evaluate the relevant UAC Local Security Policy settings under Security Options
'User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode' offers options such as 'Prompt for consent on the secure desktop', 'Prompt for credentials on the secure desktop', and 'Prompt for consent for non-Windows binaries'.
Setting this policy to 'Prompt for credentials on the secure desktop' directly satisfies the requirement for administrative users.

Anahtar Kavram

Configuring User Account Control (UAC) elevation prompt behaviors via Local Security Policy (secpol.msc)
Tahmini Süre:1m 0s
Soru 1430Soru

A desktop analyst receives a ticket regarding a corporate Windows 11 computer that has been behaving erratically, showing unauthorized background processes modifying system configurations. The analyst completes the initial symptom verification and immediately disconnects all Ethernet and Wi-Fi connections to prevent lateral movement across the internal subnet. Following standard CompTIA best-practice methodology for malware remediation, which action must the analyst perform NEXT before updating anti-malware definitions and running remediation scans?

Cevabı ve açıklamayı göster

Cevap: Disable Windows System Restore to prevent infected files from being saved into persistent backup snapshots.

Cevap

Disable Windows System Restore to prevent infected files from being saved into persistent backup snapshots.
The CompTIA 7-step malware remediation process specifies the following strict order: 1. Identify malware symptoms, 2. Isolate infected systems, 3. Disable System Restore (in Windows), 4. Remediate infected systems (update anti-malware signatures, scan and remove threats), 5. Schedule scans and run updates, 6. Enable System Restore and create a restore point, 7. Educate the user. Because the analyst has already verified symptoms and isolated the machine from the network, the mandatory next action is to disable System Restore.

Adım Adım Çözüm

1
Identify current state in the 7-step malware remediation process
Symptom verification (Step 1) and system isolation (Step 2) have already been completed by disconnecting network interfaces.
Determining the current remediation phase dictates the mandatory subsequent action.
2
Identify Step 3 of CompTIA standard remediation procedures
Step 3 specifies disabling System Restore in Windows.
If System Restore remains active during malware presence, malicious code or infected executable pointers can be saved into system restore points, leading to re-infection if restored later.
3
Select the correct action matching Step 3
Disabling System Restore purges unverified restore points prior to anti-malware updates (Step 4a) and scanning (Step 4b).
This guarantees that clean system images can eventually be created post-remediation without lingering malicious restore files.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process Execution
Soru 1431Soru

An IT technician is troubleshooting an older 32-bit custom accounting application on a Windows 11 Enterprise workstation. When standard users run the application, it appears to function normally and save configuration changes, but these changes are invisible to other users on the same machine. When an administrator logs in and runs the application, the application fails to load those user settings. What Windows User Account Control (UAC) feature is responsible for this behavior?

Cevabı ve açıklamayı göster

Cevap: UAC file and registry virtualization, which redirects writes from protected directories to %LocalAppData%\VirtualStore for standard user accounts.

Cevap

UAC file and registry virtualization redirects write operations from protected system directories to a per-user VirtualStore directory when non-administrative accounts run legacy 32-bit applications.
The correct answer correctly identifies UAC file and registry virtualization. To maintain compatibility with older 32-bit applications that expect write access to system folders (such as C:\Program Files) or system registry hives (HKLM\Software), UAC silently redirects standard user write attempts to %LocalAppData%\VirtualStore. This allows the application to function without triggering access denied errors, but isolates the saved data to that specific standard user profile.

Adım Adım Çözüm

1
Analyze the application behavior described in the scenario.
Standard users can save settings without error, but settings are isolated per user and not visible globally or to administrators.
This behavior indicates that file writes intended for shared system locations (e.g., C:\Program Files) are being redirected to user-specific locations.
2
Identify the Windows security mechanism responsible for backwards compatibility with legacy applications.
User Account Control (UAC) includes File and Registry Virtualization.
Legacy 32-bit applications without a requestedExecutionLevel manifest write to %LocalAppData%\VirtualStore instead of failing due to denied access to protected system paths.
3
Evaluate why administrators do not see these settings.
Administrative accounts bypass UAC virtualization and write directly to protected global directories.
Since the administrator writes to C:\Program Files directly, changes saved in a standard user's %LocalAppData%\VirtualStore are not read during administrative execution.

Anahtar Kavram

UAC File and Registry Virtualization
Soru 1432Soru

A field technician is diagnosing several video display and projector issues across an office site. Match each reported display symptom on the left to its correct hardware cause or corrective troubleshooting action on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

A conference room projector shuts down unexpectedly after 10 minutes of operation and displays a flashing thermal indicator LED.
A laptop display remains dark during startup, but desktop icons can be dimly seen when a bright flashlight is pointed directly at the panel.
A ceiling-mounted projector displays an image that is noticeably wider at the top of the projection screen than at the bottom.
A graphics workstation displays persistent, multi-colored checkerboard patterns and rendering glitches across the screen during 3D applications.

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Each display symptom matches its respective root cause: 1) Thermal shutdown maps to clogged dust filters or blocked vents; 2) Faint image under flashlight light maps to a failed backlight inverter or illumination circuit; 3) Uneven top/bottom image width maps to keystone distortion needing alignment; 4) Graphical checkerboard artifacts map to failing VRAM or GPU hardware.
Each pair reflects an established hardware symptom-to-cause relationship in CompTIA A+ troubleshooting: thermal LED shutdowns correlate to blocked airflow; faint image under flashlight corresponds to inverter/backlight failure; unequal horizontal edges point to keystone distortion; and screen artifacting points to VRAM or GPU hardware fault.

Adım Adım Çözüm

1
Analyze thermal shutdown symptom on the projector.
Identify that automatic power-offs paired with a thermal light stem from poor heat dissipation due to clogged dust filters or obstructed cooling vents.
Projectors contain internal thermal sensors that trigger an emergency shutdown to prevent lamp and chip damage when airflow is constricted.
2
Analyze the dark laptop screen with faint image visible under external lighting.
Determine that the liquid crystal display generates pixels correctly, but the backlight system (inverter/backlight) lacks power or has failed.
Shining a light directly onto the screen bypasses the defective internal backlight to reveal the functioning LCD screen contents underneath.
3
Analyze the trapezoidal distortion on the projector output.
Recognize that geometric distortion where top and bottom widths differ is fixed via keystone adjustment.
Keystone distortion occurs when the projector lens is not perfectly perpendicular to the projection surface.
4
Analyze graphical artifacts such as checkerboard patterns during graphics rendering.
Attribute persistent visual corruption to failing VRAM or an overheating GPU.
Hardware-level video memory corruption directly distorts rendered framebuffers stored on the expansion card.

Anahtar Kavram

Video, Display, and Projector Troubleshooting
Tahmini Süre:1m 30s
Soru 1433Soru

A field technician is performing a clean installation of Windows 11 on a workstation equipped with a hardware RAID storage controller. During the setup process, the installer reaches the disk selection screen ("Where do you want to install Windows?"), but no storage volumes are detected or displayed. The technician verifies that the RAID volume is configured correctly and reported as healthy within the controller BIOS. Which of the following is the best step for the technician to take to make the target drive visible to the Windows installer?

Cevabı ve açıklamayı göster

Cevap: Select the Load driver option on the disk selection screen and supply the specific controller drivers via a USB drive.

Cevap

The technician should select the Load driver option on the partition selection screen and load the appropriate RAID storage controller driver from an external USB drive.
When performing an OS installation on systems with hardware RAID controllers or specialized storage host adapters, the standard Windows Setup image may lack native inbox drivers for the controller. Selecting the Load driver prompt on the 'Where do you want to install Windows?' screen allows the technician to browse to external media (such as a USB drive) and load the manufacturer's storage controller driver, making the target disk array visible for partitioning and installation.

Adım Adım Çözüm

1
Identify the cause of missing storage drives during Windows Setup.
Recognize that Windows Setup lacks generic inbox drivers for the hardware RAID storage controller.
When Windows setup cannot communicate with the storage host bus adapter, connected drives are not enumerated.
2
Obtain and prepare the storage controller drivers.
Copy the uncompressed driver files (.inf, .sys, .cat) to a flash drive.
Windows Setup requires direct access to driver INF files during the setup GUI stage.
3
Load the driver within Windows Setup.
Click Load driver on the disk selection screen, browse to the USB media, select the driver, and complete driver initialization.
Loading the driver enables the setup wizard to recognize the storage controller and display available RAID volumes for installation.

Anahtar Kavram

Mass Storage Controller Driver Loading During Windows Installation
Tahmini Süre:1m 15s
Soru 1434Soru

A user reports that a custom accounting application freezes and crashes periodically while generating financial reports on a Windows workstation. A technician needs to examine the detailed crash log information (such as the faulting module) and monitor real-time memory usage for the application process. Which TWO of the following tools should the technician use?

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Event Viewer to review the Application log for crash details and faulting module names; Task Manager to observe real-time CPU and memory utilization of the application process

Cevap

The technician should use Event Viewer to examine crash log details and faulting modules, and Task Manager to monitor real-time CPU and memory utilization.
Event Viewer records detailed application crash event logs (including faulting module information), while Task Manager provides live tracking of system resources (such as RAM and CPU utilization) to diagnose resource leaks and performance spikes.

Adım Adım Çözüm

1
Open Event Viewer and navigate to Windows Logs > Application to locate the crash event entry.
Identifies the specific faulting module and exception code associated with the application crash.
Event logs contain detailed post-crash diagnostics generated by the operating system.
2
Launch Task Manager and view the Processes tab while running the application report.
Monitors active RAM and CPU utilization to detect excessive memory consumption or spikes.
Real-time performance metrics help isolate resource leaks causing application freezes.

Anahtar Kavram

Troubleshooting Windows Application Crashes and Performance Issues
Tahmini Süre:1m 0s
Soru 1435Soru

An IT technician is installing several new smart security cameras across an office building. These embedded IoT devices connect directly to the local network. Which of the following actions should the technician take first to prevent unauthorized administrative access to these devices?

Cevabı ve açıklamayı göster

Cevap: Change the factory default administrative password on each camera.

Cevap

Change the factory default administrative password on each camera.
The correct answer highlights changing factory default administrator credentials. Embedded systems and smart IoT devices often ship with standard passwords published in public manuals. Replacing these default credentials immediately upon setup blocks unauthorized administrative access.

Adım Adım Çözüm

1
Identify the primary threat vector for newly deployed embedded/IoT hardware.
Recognize that IoT devices are frequently targeted using publicly known default vendor login credentials.
Manufacturers ship embedded devices with uniform default passwords that attackers easily exploit.
2
Evaluate the initial security baseline requirements.
Determine that updating administrative credentials before connecting or exposing devices to the broader network is the critical first defense.
Modifying default logins immediately eliminates automated script-kiddie and botnet compromise risks.

Anahtar Kavram

Embedded System and IoT Hardening
Tahmini Süre:45s
Soru 1436Soru

A systems administrator needs to deploy an enterprise accounting application on several Windows 11 Pro workstations located in an isolated laboratory network without internet access. The application setup wizard requires Microsoft .NET Framework 3.5 to be installed as a prerequisite before setup can proceed. The administrator mounts a Windows 11 installation ISO image assigned to drive letter D:. Which of the following commands should the administrator execute to install the required application prerequisite offline?

Cevabı ve açıklamayı göster

Cevap: dism /online /enable-feature /featurename:NetFx3 /all /source:D:\sources\sxs /limitaccess

Cevap

Execute the Deployment Image Servicing and Management (DISM) tool with the /online, /enable-feature, /source, and /limitaccess parameters to pull the .NET Framework 3.5 files from the mounted installation media.
The command specifying DISM with the /online, /enable-feature, /source:D:\sources\sxs, and /limitaccess switches is the correct approach. It enables optional feature dependencies like .NET Framework 3.5 directly from local media without requiring an internet connection.

Adım Adım Çözüm

1
Identify the missing application prerequisite and environment constraints.
The target system requires .NET Framework 3.5, but the system is isolated from the internet.
Windows 10 and 11 do not include the binary payload for legacy .NET Framework 3.5 in the default active OS footprint.
2
Locate the offline installation source payload on the installation media.
The installation files are present under D:\sources\sxs.
The side-by-side (sxs) folder on Windows installation media contains the compressed feature payload files for optional components.
3
Run DISM with flags pointing to the local payload directory and preventing online fallback.
The feature installs successfully offline.
The /limitaccess switch prevents DISM from attempting to contact Windows Update, relying strictly on the designated /source path.

Anahtar Kavram

Offline Application Prerequisite Installation using DISM
Soru 1437Soru

A security analyst is defining baseline system hardening guidelines for enterprise workstations deployed in a corporate environment. The objective is to mitigate legacy network credential spoofing vulnerabilities and reduce the local attack surface against targeted brute-force attempts on default administrative privileges. Which of the following technical hardening measures should be implemented to achieve these specific security objectives? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Disable built-in Guest accounts and rename default local Administrator accounts.; Disable legacy name resolution protocols including LLMNR and NetBIOS over TCP/IP.

Cevap

Disabling built-in Guest accounts and renaming default Administrator accounts, along with disabling legacy name resolution protocols like LLMNR and NetBIOS over TCP/IP, are the proper technical controls to satisfy these hardening requirements.
The correct hardening measures involve disabling built-in Guest accounts and renaming default local Administrator accounts to restrict local account exploitation, as well as disabling unneeded legacy name resolution protocols (LLMNR and NetBIOS over TCP/IP) to prevent local broadcast spoofing and credential sniffing.

Adım Adım Çözüm

1
Identify local account hardening controls to minimize brute-force targeting of well-known accounts.
Disabling the built-in Guest account removes unauthenticated access, and renaming the default Administrator account prevents automated targeted attacks against known SID/username combinations.
Default administrative account names are primary targets for automated exploits and dictionary attacks.
2
Identify network protocol hardening controls to mitigate local network spoofing.
Disabling LLMNR and NetBIOS over TCP/IP prevents falling back to unauthenticated broadcast name resolution when DNS fails.
Attackers exploit fallback broadcast protocols like LLMNR/NBT-NS using tools like Responder to harvest NTLM challenge responses.
3
Evaluate and eliminate incorrect administrative tool and physical control options.
Event Viewer is an auditing tool rather than a network filter, and physical security controls do not mitigate remote network-based exploits.
Workstation hardening requires applying appropriate logical security configurations matching the specific threat vector.

Anahtar Kavram

Workstation Hardening and Best Practices
Soru 1438Soru

A network administrator is setting up a new wireless network for a corporate accounting department. The company's security policy mandates that every employee authenticates using their unique domain credentials and that authentication requests are handled centrally. Which of the following components or standards should the administrator configure to achieve this deployment? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: WPA3-Enterprise operating mode; A RADIUS server to handle 802.1X authentication requests

Cevap

The administrator should implement WPA3-Enterprise operating mode and configure a RADIUS server to handle 802.1X authentication requests.
Deploying wireless security with central domain credential verification requires an 802.1X architecture utilizing a RADIUS server for authentication, combined with WPA3-Enterprise mode for robust wireless frame encryption.

Adım Adım Çözüm

1
Analyze authentication and security requirements
The scenario requires individual domain authentication and centralized account management, ruling out Personal (PSK/SAE) modes.
Personal modes use a shared secret key for all users, which fails to support individual user accountability.
2
Select protocol and server components
Combine WPA3-Enterprise with an 802.1X RADIUS server.
WPA3-Enterprise leverages 802.1X to pass authentication requests to a backend RADIUS server connected to Active Directory.

Anahtar Kavram

Wireless Enterprise Authentication (802.1X / RADIUS / WPA3-Enterprise)
Soru 1439Soru

A systems analyst is reviewing recent security incident reports at a medium-sized enterprise. In the first incident, several employees in the marketing department received SMS text messages claiming their corporate email passwords had expired and prompting them to log into a malicious link. In the second incident, an unidentified individual wearing a fake delivery driver uniform entered the office building lobby and presented a falsified work order to convince the receptionist to grant access past the security desk. Which of the following social engineering threat types were demonstrated in these scenarios? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Smishing; Pretexting

Cevap

The threat types demonstrated are Smishing and Pretexting.
The scenario highlights two distinct social engineering vectors. The SMS messages directing users to credential-harvesting links represent smishing. The attacker using a fake delivery uniform and fake documentation to persuade the receptionist into allowing physical access represents pretexting.

Adım Adım Çözüm

1
Analyze the first incident involving SMS text messages.
Using SMS to deliver phishing links targeting credential theft is defined as Smishing.
Smishing specifically refers to phishing vector attacks conducted over Short Message Service (SMS).
2
Analyze the second incident involving the fake delivery driver uniform and falsified work order.
Inventing a false persona and scenario to gain physical entry is defined as Pretexting.
Pretexting focuses on establishing a plausible background story or role to manipulate victims into complying with requests.

Anahtar Kavram

Social engineering attack classification (digital vs. physical vectors)
Soru 1440Soru

A user on a Windows 11 workstation reports that local file searches in Windows Explorer take an unusually long time and often fail to return recently added documents stored in a newly created directory (C:\ProjectFiles). A support technician needs to add this folder path to the operating system's automated file crawl locations to improve search performance. Which Control Panel applet should the technician use to achieve this?

Cevabı ve açıklamayı göster

Cevap: Indexing Options

Cevap

The technician should open the Indexing Options Control Panel applet to include the specified directory in the Windows Search index.
The correct applet is Indexing Options. It allows technicians and users to specify which folders and file extensions are cataloged by Windows Search, directly addressing slow or incomplete search results for custom directory paths.

Adım Adım Çözüm

1
Identify the core problem
Local searches are slow and missing files because the target directory (C:\ProjectFiles) is outside default indexed locations.
Windows Search only indexes specified directories by default to optimize system resources.
2
Select the appropriate utility
Choose the Indexing Options utility in the Windows Control Panel.
Indexing Options is designed specifically to modify indexed locations, rebuild search indexes, and manage file properties indexed by the system.
3
Configure the directory path
Click Modify in Indexing Options and select the check box for C:\ProjectFiles.
Adding the location ensures the Windows Search service continuously catalogs files in that path for fast retrieval.

Anahtar Kavram

Windows Indexing Options Applet Configuration
Tahmini Süre:1m 15s
ÖncekiSayfa 72 / 178Sonraki
Tüm alıştırma soruları — CompTIA A+ (Core 1 & Core 2) | Examkin