Tüm alıştırma soruları

3551 soru

Soru 1461Soru

An IT technician is preparing to decommission several company workstations containing a mix of Solid-State Drives (SSDs) and enterprise Magnetic Hard Disk Drives (HDDs). Company policy requires that all data on the retired drives be rendered completely unrecoverable according to NIST sanitization guidelines before handing the hardware off to a third-party recycler, and that proof of disposition be retained for regulatory compliance. Which of the following steps should the technician take to satisfy these requirements? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Perform an ATA Secure Erase command on the SSDs to purge all flash memory blocks.; Obtain and archive a formal Certificate of Destruction from the recycling vendor detailing drive serial numbers.

Cevap

The technician should perform an ATA Secure Erase on the SSDs to purge the flash memory blocks and obtain a formal Certificate of Destruction detailing serial numbers from the recycling vendor.
ATA Secure Erase sends firmware-level commands to reset all storage blocks on solid-state drives, rendering the data completely unrecoverable while keeping hardware compliant with sanitization standards. Additionally, obtaining a Certificate of Destruction provides legal and auditing proof that specific hardware assets were destroyed or sanitized according to established standards.

Adım Adım Çözüm

1
Identify media types and select appropriate sanitization methods.
Recognize that SSDs require logical purging methods like ATA Secure Erase or physical shredding, whereas magnetic media can be degaussed or shredded.
Degaussing is ineffective on flash memory storage (SSDs).
2
Execute drive sanitization commands.
Run ATA Secure Erase directly through drive firmware commands to reset flash blocks.
Standard OS formatting leaves data recoverable, whereas firmware-level ATA commands ensure complete data erasure.
3
Obtain compliance documentation.
Collect a signed Certificate of Destruction from the disposal vendor listing all drive serial numbers.
Retaining official audit logs fulfills corporate policy and regulatory compliance requirements.

Anahtar Kavram

Data Sanitization and Disposal Compliance
Soru 1462Soru

A desktop support technician is configuring a Windows workstation for a network administrator. The technician needs to adjust the system's virtual memory (paging file) size to optimize performance and enable the legacy Telnet Client feature for remote device management. Which of the following Control Panel applets must the technician use to perform these configurations? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: System; Programs and Features

Cevap

The technician must use System and Programs and Features.
Configuring virtual memory (paging file) size requires opening the System applet in Control Panel and navigating to Advanced system settings under Performance options. Installing optional operating system components such as the Telnet Client requires accessing the Programs and Features applet and selecting 'Turn Windows features on or off'.

Adım Adım Çözüm

1
Identify the Control Panel applet responsible for virtual memory management.
Opening System applet -> Advanced system settings -> Performance Settings opens the Virtual Memory dialog box to adjust the paging file size.
System properties house operating system performance, visual effects, and virtual memory allocation parameters.
2
Identify the Control Panel applet responsible for enabling optional Windows components.
Opening Programs and Features -> 'Turn Windows features on or off' allows checking the Telnet Client checkbox to install the feature.
Windows optional features and components are managed through the Programs and Features applet.

Anahtar Kavram

Windows Control Panel Utilities navigation and utility identification
Soru 1463Soru

A system administrator is hardening a fleet of standalone Windows 11 desktops used by shift workers in a medical laboratory. The security compliance baseline requires prohibiting automatic execution of files from removable storage media, disabling unused guest access, and preventing unauthorized observers from viewing previously logged-on usernames at the Windows sign-in screen. During audit testing, inserting a USB flash drive still presents a pop-up menu allowing users to open media files, and the sign-in screen continues to display the username of the last technician who logged in. Which of the following policy configurations should the administrator implement to resolve both compliance issues?

Cevabı ve açıklamayı göster

Cevap: Configure 'Turn off AutoPlay' for all drives in Local Group Policy and enable the Security Setting 'Interactive logon: Do not display last signed-in'.

Cevap

Configure 'Turn off AutoPlay' for all drives in Local Group Policy and enable the Security Setting 'Interactive logon: Do not display last signed-in'.
Configuring 'Turn off AutoPlay' for all drives within Group Policy prevents Windows from displaying execution prompts or automatically running content when removable USB media is inserted. Additionally, configuring the Security Setting 'Interactive logon: Do not display last signed-in' under Local Security Policy prevents the operating system from revealing the account name of the last user who logged in, fulfilling both required hardening controls.

Adım Adım Çözüm

1
Identify the mechanism controlling removable media execution prompts.
AutoPlay handles interactive media prompts and hardware action choices when USB drives are attached.
Setting 'Turn off AutoPlay' for all drives under Computer Configuration > Administrative Templates > Windows Components > AutoPlay Policies prevents interactive media prompts.
2
Identify the Local Security Policy controlling sign-in screen username exposure.
The policy 'Interactive logon: Do not display last signed-in' located under Local Policies > Security Options hides the previously logged-in username.
This mitigates shoulder surfing and username harvesting threats on shared shift-work workstations.

Anahtar Kavram

Workstation Hardening Policies (AutoPlay and Interactive Logon Security)
Tahmini Süre:2m 0s
Soru 1464Soru

An IT security technician is decommissioning a magnetic Hard Disk Drive (HDD) that stored highly sensitive enterprise financial data. To maintain compliance and follow industry best practices, the technician must execute a complete sanitization, destruction, and chain-of-custody lifecycle protocol. What is the correct sequence of steps the technician should take from initial decommissioning to final verification?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The proper sequence begins with establishing chain-of-custody documentation, followed by logical purging (ATA Secure Erase), physical demagnetization (degaussing), mechanical destruction (shredding), and concluding with obtaining a Certificate of Destruction.
The complete asset disposal lifecycle requires establishing chain of custody first to track media accountability, followed by logical purging (ATA Secure Erase) to protect data in transit. Magnetic sanitization (degaussing) and physical destruction (shredding) ensure irreversible destruction. Finally, auditing and archiving a formal Certificate of Destruction closes the compliance loop.

Adım Adım Çözüm

1
Establish initial accountability and tracking.
Drive serial number is logged into the chain-of-custody tracking software.
Tracking prevents unauthorized movement or loss of sensitive media prior to sanitization.
2
Execute logical data sanitization.
Drive data is purged using an ATA Secure Erase operation while still attached to storage hardware.
Purging media prior to physical removal mitigates risk if media is intercepted before physical destruction.
3
Apply magnetic sanitization.
Drive platters are exposed to a degausser, rendering magnetic tracks unreadable and drive electronics non-functional.
Degaussing destroys magnetic domains on spinning platters, preventing data recovery.
4
Perform physical destruction.
The degaussed drive is physically shredded into small fragments.
Physical destruction guarantees complete physical impossibility of media reconstruction.
5
Finalize compliance and auditing logs.
A Certificate of Destruction is received, verified against serial numbers, and archived.
Provides legal and regulatory proof that sensitive data was handled according to compliance standards.

Anahtar Kavram

Chain of Custody and Secure Data Disposition Lifecycle for Magnetic Media
Soru 1465Soru

An IT support specialist is inspecting a dot-matrix impact printer used in a shipping warehouse. Workers report that while multi-part carbon forms are printing, a thin, continuous horizontal white gap appears across every row of text on the printed page. Which of the following hardware components is most likely defective?

Cevabı ve açıklamayı göster

Cevap: A bent or broken pin within the printhead assembly

Cevap

A bent or broken pin within the printhead assembly
In a dot-matrix impact printer, the printhead contains a matrix of small metal pins that strike an inked ribbon to form text and images on paper. When one pin is broken or stuck inside the printhead assembly, it leaves a continuous horizontal white blank space through every line of printed text.

Adım Adım Çözüm

1
Analyze the observed printing defect symptom.
Identified a continuous horizontal white line cutting through printed characters on a dot-matrix impact printer.
Impact printers use a grid of solenoid-actuated pins to strike the ribbon against the paper.
2
Correlate printer mechanics with the missing print artifact.
A specific pin in the vertical column array is failing to actuate.
If one pin is damaged, stuck, or broken, that specific row position remains unprinted across every line of text.

Anahtar Kavram

Impact Printer Printhead Pin Failure
Tahmini Süre:1m 0s
Soru 1466Soru

An enterprise administrator is deploying security policies for a fleet of mobile devices used by field technicians accessing sensitive customer data. The organization requires that all corporate emails, internal documents, and proprietary tools operate within an encrypted, isolated workspace that prevents copy-paste capabilities into personal applications. Furthermore, IT must be able to perform a targeted removal of only enterprise data when an employee leaves the company, without affecting personal photos or personal applications. Which of the following controls should the administrator implement to satisfy these requirements?

Cevabı ve açıklamayı göster

Cevap: Containerization combined with Mobile Application Management (MAM) policies

Cevap

Containerization combined with Mobile Application Management (MAM) policies is the correct control.
Containerization creates a secure, encrypted sandbox on the mobile device that isolates corporate applications and data from personal applications. Combined with Mobile Application Management (MAM), administrators can enforce Data Loss Prevention (DLP) rules such as restricting copy-paste actions between enterprise and personal apps, and perform a selective wipe to remove only corporate credentials and data when an employee leaves.

Adım Adım Çözüm

1
Analyze the technical requirements in the scenario.
Identified key requirements: isolated/encrypted workspace, prevention of copy-paste between corporate and personal apps, and selective wiping of business data only.
Understanding the precise operational constraints is essential for selecting the appropriate Mobile Device Management security control.
2
Evaluate technologies that enforce data isolation and selective data destruction.
Containerization creates a sandboxed storage boundary separating enterprise apps from personal apps, enforcing clipboard isolation. Mobile Application Management (MAM) enables selective remote wipe capabilities.
Containerization and MAM directly fulfill both data separation and targeted wipe requirements.
3
Eliminate options that misapply full-device controls or network/physical security features.
Full-device encryption and full remote wiping destroy all device data rather than performing a selective wipe. Geofencing and wireless authentication address location boundaries and network security rather than app-level sandboxing.
Alternative choices fail to address the application sandboxing and selective wipe constraints.

Anahtar Kavram

Mobile Containerization and MAM (Selective Wipe)
Soru 1467Soru

A technician is troubleshooting a desktop computer that powers on when the power button is pressed, but it fails to complete the Power-On Self-Test (POST) and continuously emits repeating single beep codes. Which sequence of steps should the technician follow to systematically isolate and resolve the memory issue?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The proper troubleshooting sequence requires isolating the system to core components, inspecting cleared memory slots, verifying motherboard functionality using a single known-good memory module, and systematically testing individual original RAM sticks.
According to CompTIA hardware troubleshooting methodology, isolating a memory POST issue requires minimizing system complexity first, inspecting physical slots, confirming system stability with a single known-good RAM module, and then testing suspect modules individually.

Adım Adım Çözüm

1
Isolate system hardware
Peripheral interference and expansion card conflicts are eliminated.
Before testing memory specifically, non-essential hardware must be removed to avoid false diagnostics.
2
Clear and inspect DIMM slots
Slots are verified clean and ready for single-channel testing.
Removing all RAM modules clears potential channel seating errors.
3
Establish a working baseline with known-good RAM
System completes POST or confirms slot integrity.
Using a known-good module verifies whether the motherboard memory bus and controller are functional.
4
Isolate defective RAM stick
The faulty RAM module is identified for replacement.
Testing original modules individually isolates the specific stick causing continuous POST beep codes.

Anahtar Kavram

RAM POST Failure Diagnostic Sequencing

Alternatif Yöntem

Consulting motherboard diagnostic LEDs or a POST card display can provide immediate status codes before pulling RAM sticks.
Tahmini Süre:1m 30s
Soru 1468Soru

A Windows workstation application has stopped responding, causing localized performance degradation. Place the standard troubleshooting steps in the correct sequence to inspect and resolve this application failure.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence is: first, press Ctrl + Shift + Esc to open Task Manager; second, locate the hung application in the Processes tab to verify high resource utilization; third, select the non-responsive application process and click End Task; fourth, open Event Viewer and navigate to the Application log to inspect crash details.
The proper troubleshooting flow requires immediate action to restore system usability before performing deep log analysis. Launching Task Manager with Ctrl + Shift + Esc provides immediate access to active processes. Identifying the frozen process on the Processes tab allows the technician to target the correct application. Executing End Task releases stuck system resources. Finally, checking the Application log in Event Viewer provides diagnostic event details for post-incident root cause analysis.

Adım Adım Çözüm

1
Launch Task Manager using the keyboard shortcut Ctrl + Shift + Esc.
Task Manager opens, displaying real-time system performance and active process lists.
You must open Task Manager before you can inspect or manage running processes.
2
Examine the Processes tab to locate the frozen or high-utilization application.
The target process status shows '(Not Responding)' or excessive resource usage.
Identifying the specific process ensures the correct application is targeted.
3
Select the application and click End Task.
The unresponsive process terminates and system responsiveness is restored.
Ending the hung task frees trapped memory and CPU cycles.
4
Open Event Viewer and check the Windows Application log for faulting module entries.
Technician gathers Event IDs and error codes for long-term remediation.
Post-incident diagnostic log review identifies root causes without keeping the system frozen.

Anahtar Kavram

Troubleshooting Unresponsive Applications and Resource Isolation Sequence
Soru 1469Soru

An organization allows employees to use personal smartphones for work under a Bring Your Own Device (BYOD) policy. The IT department needs the ability to erase corporate emails and sensitive company documents from a device if an employee leaves the company, while leaving the employee's personal data untouched. Which of the following features or security controls best achieves this capability?

Cevabı ve açıklamayı göster

Cevap: Containerization with selective wipe

Cevap

Containerization with selective wipe
Containerization segregates corporate applications and data into a isolated, encrypted sandbox managed by Mobile Device Management (MDM). If an employee leaves the company or a device is decommissioned from BYOD use, administrators can perform a selective wipe, which deletes only the corporate container while leaving personal photos, text messages, and personal applications untouched.

Adım Adım Çözüm

1
Identify the operational requirement
The requirement calls for removing company data from a personal device without disturbing the user's personal files.
BYOD policies require protecting enterprise data while maintaining employee privacy.
2
Evaluate mobile device management (MDM) features
Containerization isolates corporate applications and stored data into a dedicated, encrypted virtual boundary.
Separating business and personal data allows granular administrative control.
3
Determine the appropriate wipe procedure
A selective wipe targets only the corporate container, preserving all personal photos, apps, and settings.
Selective wipe satisfies both security and privacy constraints.

Anahtar Kavram

Mobile device containerization and selective wipe in BYOD deployment models
Soru 1470Soru

A desktop support technician is tasked with modifying the User Account Control (UAC) behavior for administrators on a newly deployed workstation running Windows 11 Home. The technician attempts to open the Local Security Policy console by running secpol.msc in the Run dialog box, but Windows displays a snap-in initialization error stating that the file cannot be found. Which of the following explains why the technician cannot access this security management tool?

Cevabı ve açıklamayı göster

Cevap: Local Security Policy (secpol.msc) is not included in the Home edition of Windows and requires Windows Pro or Enterprise.

Cevap

Local Security Policy (secpol.msc) is an advanced administrative feature that is excluded from Windows Home editions, requiring a Windows Pro or Enterprise edition to be accessed.
Microsoft limits advanced management utilities like Local Security Policy (secpol.msc) and Local Group Policy Editor (gpedit.msc) to Windows Professional, Enterprise, and Education editions. Attempting to run secpol.msc on a Windows Home edition results in an error because the component binaries and management policies are not installed on that edition.

Adım Adım Çözüm

1
Identify the administrative tool requested
The requested tool is secpol.msc (Local Security Policy).
Secpol.msc is used to configure security options, account policies, and User Account Control (UAC) enforcement rules.
2
Evaluate edition feature constraints for Windows 11 Home
Windows Home editions intentionally exclude Local Security Policy (secpol.msc) and Group Policy Editor (gpedit.msc).
Microsoft reserves advanced security management tools and domain management capabilities for business and enterprise editions (Pro, Enterprise, Education).
3
Determine the necessary resolution
Upgrade the workstation to Windows 11 Pro or Enterprise to gain access to secpol.msc.
Features absent due to OS edition limitations cannot be enabled via permissions or standard applets without an edition upgrade.

Anahtar Kavram

Windows Edition Feature Differences and Security Policy Management
Tahmini Süre:1m 0s
Soru 1471Soru

A technician is troubleshooting a ceiling-mounted projector in a corporate conference room. Meeting participants report two specific issues: the projected image periodically cuts out completely for a few seconds before returning, and the image displayed on the screen appears trapezoidal (significantly wider at the top than at the bottom). Which of the following actions should the technician take to resolve these issues? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Clean or replace the projector air filters and clear blocked ventilation pathways.; Adjust the projector keystone configuration settings or tilt position.

Cevap

The technician should clean or replace the projector's air filters to prevent thermal overload shutdowns and adjust the projector's keystone settings to eliminate trapezoidal image distortion.
Cleaning or replacing the projector air filter addresses thermal overload conditions that cause the projector to turn off its lamp intermittently to protect internal components. Adjusting the keystone settings compensates for physical angle offset between the projector lens and the screen, squaring the trapezoidal image.

Adım Adım Çözüm

1
Diagnose the intermittent cutout symptom.
Identify that thermal protection causes the lamp to turn off temporarily when airflow is restricted by dust buildup.
Air filters maintain proper thermal dissipation; when clogged, overheating causes safety thermal shutdowns.
2
Diagnose the trapezoidal image distortion symptom.
Determine that the projector lens angle relative to the screen is creating a skewed projection.
Keystone correction digitally or mechanically reshapes the image so that top and bottom edges are parallel.

Anahtar Kavram

Projector Maintenance and Image Alignment
Soru 1472Soru

A field systems engineer is servicing a Windows workstation at a remote branch office after local endpoint monitoring software flagged rogue keylogger activity. The engineer has physically disconnected the machine from the network, verified that the host is fully quarantined, and downloaded the latest anti-malware definition signatures onto an isolated USB drive. Which step must the engineer perform NEXT in accordance with standard malware remediation procedures prior to executing the scan and removal process?

Cevabı ve açıklamayı göster

Cevap: Disable System Restore in Windows.

Cevap

Disable System Restore in Windows before running the anti-malware remediation scan.
According to the official CompTIA 7-step malware remediation process, the exact sequence is: 1. Identify malware symptoms, 2. Quarantine infected systems, 3. Disable System Restore, 4. Remediate infected systems (update anti-malware signatures, scan, and remove), 5. Schedule updates and scans, 6. Enable System Restore and create a restore point, 7. Educate the end user. Since the system has already been quarantined and update files obtained, the required next step before performing the remediation scan is to disable System Restore.

Adım Adım Çözüm

1
Analyze the completed steps in the CompTIA 7-step malware remediation process.
Step 1 (Identify malware) and Step 2 (Quarantine infected systems) have already been completed.
The scenario states that the keylogger was identified, the host network connection was severed (quarantined), and definition updates were acquired.
2
Determine the mandatory next sequential step before scanning and removing the malware (Step 4).
Step 3 is disabling System Restore in Windows.
Disabling System Restore purges existing restore points and prevents Windows from automatically backing up infected binaries while removal tools are running.
3
Confirm why post-remediation steps must not be performed prematurely.
Scheduling updates (Step 5), creating new restore points (Step 6), and end-user education (Step 7) must occur only after successful remediation.
Performing post-remediation steps prior to scanning leaves active malware payloads in place and jeopardizes system recovery integrity.

Anahtar Kavram

CompTIA 7-Step Malware Remediation Process Order
Tahmini Süre:2m 0s
Soru 1473Soru

A network security administrator is standardizing wireless access controls across corporate headquarters and remote locations. Match each wireless security control or protocol to its primary operational feature.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

WPA3-Personal
WPA3-Enterprise
802.1X / RADIUS
Captive Portal

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

WPA3-Personal matches Simultaneous Authentication of Equals (SAE); WPA3-Enterprise matches 192-bit cryptographic strength options; 802.1X / RADIUS matches centralized AAA authentication via EAP; Captive Portal matches web traffic interception for guest authentication/AUP acceptance.
Each wireless security mechanism is correctly paired to its underlying protocol or operational behavior: WPA3-Personal uses SAE to defend against offline dictionary attacks; WPA3-Enterprise provides optional 192-bit cryptographic mode; 802.1X/RADIUS supplies centralized AAA authentication using EAP; Captive Portal handles guest traffic redirection and policy acceptance.

Adım Adım Çözüm

1
Analyze the personal vs enterprise authentication standards
Identify WPA3-Personal as utilizing SAE and WPA3-Enterprise as offering optional 192-bit cryptographic suites.
SAE provides robust protection against password cracking for shared passphrases, while Enterprise mode focuses on high-grade cryptographic suites.
2
Evaluate enterprise central authentication infrastructure
Associate 802.1X / RADIUS with centralized account management using EAP protocols.
802.1X provides port-based access control authenticating individual domain users against a central RADIUS server.
3
Determine guest access and policy enforcement methods
Link Captive Portal to web redirection for guest user authentication and AUP consent.
Captive portals manage guest access by intercepting HTTP/HTTPS traffic until access conditions are fulfilled.

Anahtar Kavram

Wireless Security Protocols and Authentication Frameworks
Soru 1474Soru

An IT support technician needs to upgrade several workstations in a desktop pool from Windows 10 Home to Windows 10 Pro to enable BitLocker drive encryption and domain join capabilities. The technician must preserve all user data, installed applications, and system configurations while minimizing system downtime. Which of the following is the most efficient method to accomplish this objective?

Cevabı ve açıklamayı göster

Cevap: Change the product key in Activation settings to a valid Windows 10 Pro key to execute an in-place edition upgrade.

Cevap

Changing the product key in Windows Activation settings to a valid Windows Pro key is the correct method for performing an in-place edition upgrade while keeping all user data and applications intact.
Entering a valid Windows Pro product key under Settings > Update & Security > Activation initiates an in-place edition upgrade. This process installs the additional feature packages for Windows Pro (such as BitLocker and Domain Join) directly onto the existing OS, preserving all user files, installed applications, and system preferences.

Adım Adım Çözüm

1
Identify the target upgrade requirements
The target is to move from Windows 10 Home to Windows 10 Pro while preserving data, applications, and settings.
Understanding whether a full OS reinstallation is required versus an edition upgrade saves significant administrative effort.
2
Evaluate Windows edition upgrade capabilities
Windows 10 supports direct in-place edition upgrades from Home to Pro simply by applying a Pro product key in Activation settings.
The underlying binaries for Pro features are already present in the OS image; updating the product key activates those features without rebuilding the OS.
3
Select the most efficient deployment method
Using the Change Product Key feature in Settings achieves the upgrade with zero data loss and minimal downtime.
Media-based clean installations or unattended re-images unnecessarily wipe user applications and configurations.

Anahtar Kavram

Windows In-Place Edition Upgrade
Soru 1475Soru

A remote IT support technician receives a call from a distressed customer whose system crashed during a high-priority business transaction. The customer is frustrated, speaking rapidly, and demanding an immediate fix. Place the following professional communication and user interaction steps in the correct chronological sequence from initial call handling to final call closure.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct chronological sequence is: (1) Actively listen and de-escalate, (2) Set expectations and request remote control permission, (3) Instruct user to close confidential/PII data, (4) Perform troubleshooting with clear non-technical explanations, and (5) Verify resolution with user and document the ticket.
The correct workflow follows standard CompTIA operational procedures for user interaction: first de-escalate and listen to establish communication; next request remote permission and set time expectations; third protect confidentiality by having the user clear PII; fourth conduct troubleshooting using clear, jargon-free explanations; and finally verify problem resolution with the user and complete formal ticket documentation.

Adım Adım Çözüm

1
Initial Customer Engagement & De-escalation
Customer feels heard and de-escalated; full problem context is gathered without interruption.
Active listening and maintaining a professional tone are required first when dealing with frustrated users.
2
Establishing Scope & Permission
User understands expected timelines and gives consent for remote access.
Proper protocol requires setting expectations and getting customer permission before taking control of their system.
3
Protecting Privacy and Confidential Information
Screen visual field is cleared of confidential and sensitive personal data.
CompTIA best practices dictate safeguarding customer privacy and PII before viewing remote screens.
4
Technical Execution with Clear Communication
Issue is resolved without confusing the customer with acronyms or technical jargon.
Keeping the customer informed using plain language builds confidence and avoids miscommunication.
5
Verification and Documentation
Issue fix is confirmed by user, customer sign-off is achieved, and incident details are recorded.
A ticket should only be closed after user verification, proper documentation, and formal customer confirmation.

Anahtar Kavram

Best practices for professional communication, customer de-escalation, privacy preservation, and remote support workflows.
Soru 1476Soru

An IT security analyst is cataloging recent security incident reports across different departments. Match each security threat scenario to its corresponding social engineering vector or attack classification.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Whaling
Piggybacking
Hoax
Logic Bomb

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Whaling matches the executive-targeted phishing scenario; Piggybacking matches entry into a secured room with employee consent; Hoax matches the false security alert instructing users to delete files; Logic Bomb matches dormant malicious code waiting for a specific trigger condition.
Each attack type matches its defined characteristic operational behavior. Whaling targets top leadership; Piggybacking exploits physical entry courtesy with mutual knowledge; Hoaxes trick personnel using deceptive false warnings; Logic Bombs execute code based on specified temporal or logic triggers.

Adım Adım Çözüm

1
Identify digital social engineering targeted by role.
Recognize that targeting C-level executives specifically for financial or corporate data theft is termed Whaling.
Whaling is a specialized sub-category of spear phishing designed to compromise high-value executive targets.
2
Analyze physical security social engineering vectors.
Differentiate Piggybacking (gaining access with consent/courtesy) from Tailgating (gaining access without consent/unnoticed).
Holding a door open intentionally for someone carrying boxes with their consent fits the exact definition of piggybacking.
3
Evaluate social engineering tactics leveraging false panic.
Identify that misleading users into causing self-harm to systems via fake warnings is classified as a Hoax.
Hoaxes exploit fear and urgency to manipulate personnel into deleting files or disrupting operations without using technical exploits.
4
Categorize software threat execution triggers.
Associate dormant code activated by event conditions (like employee status change or specific date) with a Logic Bomb.
Logic bombs execute malicious payloads based on boolean logical triggers built into the codebase.

Anahtar Kavram

Classification of Social Engineering and Threat Types
Soru 1477Soru

A security analyst is hardening standalone Windows 11 Pro workstations deployed in a high-security public kiosk environment. The organization requires that whenever a standard user attempts to launch an application or script requiring administrative elevation, Windows must automatically reject the request immediately without displaying a credential prompt. Which Local Security Policy setting under Security Options directly enforces this requirement?

Cevabı ve açıklamayı göster

Cevap: Set "User Account Control: Behavior of the elevation prompt for standard users" to "Automatically deny elevation requests"

Cevap

Set "User Account Control: Behavior of the elevation prompt for standard users" to "Automatically deny elevation requests"
Configuring 'User Account Control: Behavior of the elevation prompt for standard users' to 'Automatically deny elevation requests' in Local Security Policy directly satisfies the security requirement by automatically blocking standard user privilege escalation attempts without popping up an administrator credential prompt.

Adım Adım Çözüm

1
Identify the target user role and requirement
The requirement specifies standard users attempting elevation on Windows 11 workstations, where requests must be automatically denied without prompting.
UAC security policies differentiate between administrators in Admin Approval Mode and standard users.
2
Locate the relevant security policy node in Windows
Open Local Security Policy (secpol.msc) and navigate to Security Settings > Local Policies > Security Options.
Advanced granular UAC behavior settings are managed via Security Options policies rather than standard GUI applets.
3
Select the correct elevation prompt policy for standard users
Configure "User Account Control: Behavior of the elevation prompt for standard users" to "Automatically deny elevation requests".
This configuration prevents standard users from elevating privileges or prompting for administrative credentials.

Anahtar Kavram

Windows Local Security Policy UAC Elevation Prompt Behavior Settings
Tahmini Süre:2m 0s
Soru 1478Soru

A corporate employee recently updated their Active Directory domain password. Following the update, the user experiences recurring account lockouts whenever attempting to access a mapped network drive from their Windows workstation. An IT technician suspects that saved authentication tokens stored on the workstation are still presenting the previous password to the network share. Which of the following Control Panel applets should the technician open to remove or update the cached vault credentials?

Cevabı ve açıklamayı göster

Cevap: Credential Manager

Cevap

Credential Manager is the correct Control Panel applet because it specifically manages stored Windows Vault credentials, web credentials, and network sign-in tokens.
Credential Manager allows users and technicians to view, edit, and delete stored credentials used for logging into websites, network drives, and domain resources. Removing the expired network entry from the Windows Credentials section prevents the workstation from silently submitting stale credentials that trigger domain account lockouts.

Adım Adım Çözüm

1
Identify the cause of recurring account lockouts after a password change.
Recognize that cached network authentication details on the local client workstation are attempting automatic logons with an expired password.
Windows caches network share authentication details so users do not have to re-enter credentials continuously.
2
Locate the Windows Control Panel utility designed to manage stored user credentials.
Select Credential Manager.
Credential Manager holds Web Credentials and Windows Credentials (Vaults) specifically intended for managing saved domain logins and network shares.
3
Modify or remove the stale entry within Windows Credentials.
The old cached password is purged, stopping automated invalid logon attempts and ending the account lockouts.
Clearing the expired entry forces Windows to prompt for the newly updated password upon the next connection attempt.

Anahtar Kavram

Credential Manager Control Panel Applet
Soru 1479Soru

An IT support specialist is tasked with ensuring that previously deleted sensitive files on a Windows workstation volume cannot be recovered using forensics tools. The operational files currently on the drive must remain intact, and the volume cannot be formatted. Which of the following command-line utilities and options should the specialist execute?

Cevabı ve açıklamayı göster

Cevap: cipher /w:C:\Data

Cevap

The command 'cipher /w:C:\Data' is the correct choice because it overwrites unallocated free disk space without erasing active files.
The 'cipher /w' command is specifically designed in Windows to remove data from available unallocated storage space. When run against a path, it allocates memory and writes three passes (zeroes, ones, and random numbers) to all free disk space, ensuring deleted files cannot be recovered while leaving active files intact.

Adım Adım Çözüm

1
Identify the administrative requirement.
The requirement demands wiping unallocated/deleted data space while preserving active files on a Windows volume.
Standard file deletion in Windows only removes directory pointers, leaving raw file data in free space until overwritten.
2
Evaluate native Windows CLI disk sanitization tools.
The 'cipher' utility with the '/w' switch (wipe) fills unused disk space with zeroes, ones, and random numbers.
Executing 'cipher /w:<directory_path>' targeted at the volume or folder path safely sanitizes deallocated clusters without affecting active data.

Anahtar Kavram

Using the cipher command to wipe unallocated disk space in Windows
Soru 1480Soru

An IT technician is preparing to harden a newly installed Windows workstation before introducing it into an enterprise environment. Place the following workstation hardening steps in the correct standard procedural sequence, from first to last.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence for workstation hardening is: 1) Change default credentials and disable unused default accounts, 2) Apply all operating system updates and security patches, 3) Disable unnecessary system services and AutoPlay/AutoRun features, and 4) Enable host-based firewall rules and anti-malware protection.
A baseline workstation hardening workflow follows a logical order: first secure user accounts and default credentials to prevent basic unauthorized access; second, apply system updates and patches to address known security flaws; third, decrease the attack surface by disabling unneeded services and automatic feature execution; and finally, enable host firewalls and anti-malware software for continuous active defense.

Adım Adım Çözüm

1
Secure account access
Default credentials are changed and unneeded built-in accounts are disabled.
Prevents unauthorized access using widely known factory default accounts.
2
Patch software vulnerabilities
The operating system is fully updated with security hotfixes.
Closes known system vulnerabilities so update routines work reliably before services are restricted.
3
Reduce system attack surface
Unused services and features like AutoPlay are turned off.
Eliminates superfluous entry points that attackers or automated scripts could exploit.
4
Deploy active defensive security controls
Host firewall rules and anti-malware defenses are active.
Establishes real-time filtering and scanning for ongoing workstation operation.

Anahtar Kavram

Standard Workstation Hardening Procedure
ÖncekiSayfa 74 / 178Sonraki
Tüm alıştırma soruları — CompTIA A+ (Core 1 & Core 2) | Examkin