Tüm alıştırma soruları

3551 soru

Soru 1761Soru

Match each remote access technology or protocol on the left with its defining operational characteristic and port specification on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Secure Shell (SSH)
Remote Desktop Protocol (RDP)
Microsoft Remote Assistance (MSRA)
Telnet

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Secure Shell (SSH) pairs with encrypted CLI over TCP port 22. Remote Desktop Protocol (RDP) pairs with full graphical control over TCP port 3389 that locks local sessions. Microsoft Remote Assistance (MSRA) pairs with invitation-based interactive session control. Telnet pairs with unencrypted cleartext CLI over TCP port 23.
Each technology is mapped according to standard network port assignments and session management behaviors. Secure Shell (SSH) encrypts terminal sessions on TCP port 22; Remote Desktop Protocol (RDP) provides exclusive GUI management on TCP port 3389; Microsoft Remote Assistance (MSRA) uses invitations for collaborative remote assistance; and Telnet sends unencrypted terminal data over TCP port 23.

Adım Adım Çözüm

1
Analyze command-line remote access tools based on security and port numbers.
SSH provides encrypted administration using TCP port 22, whereas Telnet sends unencrypted cleartext data over TCP port 23.
Distinguishing secure protocols from insecure legacy protocols is critical for operational procedures.
2
Analyze Windows graphical remote access tools based on session handling and user interaction.
RDP uses TCP port 3389 and creates an exclusive session that locks the local monitor, whereas MSRA uses user-initiated invitations to allow dual-view interactive troubleshooting.
RDP is designed for remote workspace access, while MSRA is designed for real-time user support.
3
Map each protocol or tool to its exact operational definition.
All four items are matched to their corresponding characteristics.
Ensures complete alignment with CompTIA remote access specifications.

Anahtar Kavram

Remote Access Protocols, Default Ports, and Operational Behaviors
Soru 1762Soru

A field technician reports that their enterprise-managed mobile smartphone is repeatedly displaying untrusted security certificate warnings when accessing internal company portals. Network logs indicate that sensitive traffic is being intercepted via a custom root certificate authority (CA) installed alongside an unapproved third-party configuration profile. Which of the following actions should the technician take FIRST to eliminate the unauthorized traffic interception?

Cevabı ve açıklamayı göster

Cevap: Remove the unauthorized configuration profile and delete its associated root certificate from the device settings.

Cevap

Removing the unauthorized configuration profile and deleting the associated root certificate from the device settings is the most effective immediate action.
Removing the unauthorized configuration profile and deleting the untrusted root certificate directly neutralizes the Man-in-the-Middle (MitM) threat by removing the malicious trust anchor responsible for SSL/TLS interception warnings.

Adım Adım Çözüm

1
Identify the cause of the untrusted certificate warning and traffic interception.
Discovered that a third-party configuration profile injected an unapproved custom root certificate onto the device.
Root CA certificates explicitly allow an entity to issue and validate trusted SSL/TLS certificates for traffic interception (Man-in-the-Middle).
2
Select the immediate remediation step to restore device trust integrity.
Access the mobile OS security settings to delete the malicious configuration profile and revoke the untrusted CA certificate.
Directly removing the malicious trust anchor stops unauthorized decrypt-and-forward proxying of HTTPS sessions.

Anahtar Kavram

Mobile Device Configuration Profile & Root Certificate Remediation
Tahmini Süre:2m 0s
Soru 1763Soru

A storage area network (SAN) engineer is preparing a change request to update the microcode on an enterprise SAN array hosting critical Virtual Desktop Infrastructure (VDI) datastores. The engineer has defined the purpose and scope of the change, completed a risk analysis regarding potential storage disruption, created a step-by-step implementation plan, and established post-implementation testing protocols. Prior to presenting this request to the Change Advisory Board (CAB) for formal authorization, which of the following mandatory change management components must the engineer add to complete the change documentation?

Cevabı ve açıklamayı göster

Cevap: A detailed rollback plan outlining specific procedures to revert the storage array microcode and configuration to its prior operational state if the update fails.

Cevap

A detailed rollback plan outlining specific procedures to revert the storage array microcode and configuration to its prior operational state if the update fails.
The correct answer emphasizes the necessity of a documented rollback plan. Standard CompTIA change management workflows mandate that every proposed change include a clear purpose, scope, risk assessment, implementation plan, rollback plan, end-user notification, CAB authorization, and post-implementation testing. Without a predefined strategy to revert changes, the risk of unrecoverable downtime is unacceptably high.

Adım Adım Çözüm

1
Analyze the change request preparation phase described in the scenario.
Identified existing components: purpose, scope, risk analysis, implementation plan, post-implementation testing, and end-user notification strategy.
CompTIA change management process mandates specific documentation requirements prior to CAB submission.
2
Evaluate missing prerequisite components for CAB submission.
Recognized that a documented rollback (backout) plan has not yet been defined.
Without a rollback plan, the organization cannot mitigate risk if the microcode update causes unforeseen system failure or data corruption.
3
Select the correct mandatory documentation step.
Determined that developing a rollback plan is the required next step before formal CAB authorization.
CAB approval requires verification that services can be safely restored to a baseline state if unexpected issues occur.

Anahtar Kavram

Core Elements of Formal Change Documentation
Soru 1764Soru

A help desk technician has just finished resolving a network printer configuration issue on a user's workstation. According to standard ticketing system workflows, which of the following elements must be recorded in the ticket's final resolution log? (Select TWO).

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: A detailed description of the troubleshooting steps performed and the specific solution applied; Confirmation that the user verified proper functionality and agreed the problem is resolved

Cevap

Proper resolution documentation requires a detailed record of the troubleshooting steps and solution applied, as well as explicit confirmation of user verification.
Complete resolution logging requires detailing the technical resolution steps and confirming with the end-user that functionality is restored. These entries establish reliable knowledge base records and ensure service quality.

Adım Adım Çözüm

1
Identify the mandatory components of a complete ticket resolution record.
Comprehensive documentation requires technical details of the resolution and proof of user verification.
Standard ticketing workflows mandate clear technical records for future reference and customer satisfaction confirmation before closing tickets.
2
Evaluate technical documentation requirements.
Documenting specific troubleshooting steps and the applied fix provides accurate historical data for the IT knowledge base.
Omitting technical steps makes it impossible for other technicians to learn from past incidents.
3
Evaluate user interaction and closure requirements.
Obtaining user verification confirms that the system operates as expected in the user's working environment.
Tickets should not be closed unilaterally without verifying that the issue is completely resolved from the end-user's perspective.

Anahtar Kavram

Incident Resolution Documentation and Verification Workflows
Tahmini Süre:1m 0s
Soru 1765Soru

A tier 2 remote support technician connects to a end-user's system to resolve a recurring application freeze that is impacting the user's daily deadline. The user expresses frustration about the downtime and asks what is taking so long. Which of the following professional communication and user interaction practices should the technician demonstrate in this situation? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Ask for explicit permission before taking control of the remote screen or interacting with the user's workspace.; Practice active listening by allowing the user to explain their frustration and issue details without interrupting.

Cevap

The technician should practice active listening without interrupting the user and obtain explicit permission before taking control of the remote desktop workspace.
The correct responses involve practicing active listening by allowing the user to describe their situation uninterrupted, as well as securing explicit permission before interacting with or controlling the customer's remote workstation environment. These actions uphold professionalism, de-escalate tension, and protect user privacy.

Adım Adım Çözüm

1
Evaluate de-escalation and listening techniques for customer interaction.
Identified that allowing the customer to express their concerns completely without interruption demonstrates active listening and maintains a professional tone.
De-escalating an anxious or frustrated user requires patience and active listening prior to diagnostic troubleshooting.
2
Apply customer property and privacy protocols during remote support.
Identified that requesting permission before initiating screen control or navigating user files respects user privacy and property.
Technicians must never take control or alter a customer's environment without prior consent.

Anahtar Kavram

Professional customer communication, active listening, and respect for customer property and privacy during remote IT support sessions.
Soru 1766Soru

A tier 1 service desk technician has finished resolving a workstation software issue caused by a corrupted application configuration file. According to standard ticketing workflow and documentation best practices, which of the following elements MUST be documented in the ticket resolution entry before it can be closed? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: The identified root cause and the specific resolution steps performed to fix the issue; Formal confirmation from the end user verifying that the application is functioning as expected

Cevap

The resolution entry must include the identified root cause along with specific steps performed, as well as formal confirmation from the end user verifying functionality.
Complete ticket closure documentation requires both technical fidelity (documenting the root cause and detailed resolution steps taken) and procedural verification (obtaining confirmation from the end user that the issue is resolved).

Adım Adım Çözüm

1
Identify mandatory ticket closure components under standard IT support guidelines.
Tickets require clear documentation of what caused the issue, what was done to fix it, and verification of user satisfaction.
Clear work notes allow knowledge base creation and prevent premature closing of unresolved issues.
2
Evaluate technical documentation details.
Recording the root cause and exact technical resolution steps ensures auditability and aids other technicians facing similar issues.
Complete resolution notes reduce mean time to resolution (MTTR) across the team.
3
Evaluate operational workflow verification steps.
User confirmation confirms that testing succeeded in the production environment from the user's perspective.
Closing a ticket without user verification leads to reopened tickets and poor service quality.

Anahtar Kavram

Incident Ticket Closure Documentation and Verification Workflow
Soru 1767Soru

A cybersecurity analyst is preparing to transfer a compromised server hard drive to an external forensic laboratory for legal analysis. The internal incident log currently includes the drive's model and serial number, the date and time of initial seizure, the acquiring technician's signature, and the secure storage room location. Which of the following details MUST be recorded on the chain-of-custody form at the moment of handoff to maintain evidence admissibility?

Cevabı ve açıklamayı göster

Cevap: The recipient's name, signature, and the exact date and time of the physical transfer

Cevap

The recipient's name, signature, and the exact date and time of the physical transfer
A chain of custody log must document a complete, unbroken record of every individual who takes possession of evidence. When transferring hardware to a third party, recording the recipient's full name, signature, and the exact timestamp of transfer is mandatory to prove the evidence was safeguarded and untampered with.

Adım Adım Çözüm

1
Identify the purpose of a chain-of-custody document
Recognize that chain of custody establishes continuous control and tracking of digital evidence from seizure to courtroom presentation.
Any gap in documentation regarding who handled evidence or when it changed hands can invalidate the evidence in court.
2
Analyze missing elements required during evidence transfer
Determined that handing over physical media to another party requires explicit sign-off by both handler and recipient.
Without the recipient's signature, name, and transfer timestamp, custody control is broken.

Anahtar Kavram

Chain of Custody Documentation Requirements
Soru 1768Soru

A remote user requests interactive help from a corporate IT technician to resolve an application configuration error. The technician needs to view the user's active desktop session and work together with the user while keeping the user's local screen active. Which remote access tool is best suited for this task?

Cevabı ve açıklamayı göster

Cevap: Microsoft Remote Assistance (MSRA)

Cevap

Microsoft Remote Assistance (MSRA)
Microsoft Remote Assistance (MSRA) allows a support technician to connect to a user's active session so both individuals can view the desktop and share control, making it ideal for interactive user assistance.

Adım Adım Çözüm

1
Identify the primary requirement of the support scenario.
The technician must interactively view and assist in the user's active session without disconnecting or locking out the local user.
Collaborative desktop troubleshooting requires both the technician and user to see the same screen simultaneously.
2
Evaluate the capabilities of the available remote access tools.
Microsoft Remote Assistance (MSRA) supports interactive desktop sharing where the local user remains connected, whereas Remote Desktop Connection locks the local screen on client Windows editions.
MSRA is designed specifically for user-assisted remote support.

Anahtar Kavram

Remote Access Tools and Desktop Sharing Capabilities
Soru 1769Soru

An IT technician discovers a workstation infected with ransomware on the corporate network. Arrange the initial incident response actions in the correct chronological order from first step to last step.

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence of incident response steps is: First, identify the security incident and confirm the threat; Second, report the incident to the designated supervisor or incident response team; Third, isolate the compromised system from the network; Fourth, preserve system evidence and document the chain of custody.
Under standard CompTIA first responder procedures, the chronological order of operations is identification, reporting to proper authorities, isolating the system to contain the threat, and preserving evidence along with chain of custody documentation.

Adım Adım Çözüm

1
Identify the incident
Confirmed ransomware infection on the workstation.
Incident identification must occur first to understand the scope and nature of the issue.
2
Report the incident
Escalated details to the security and management team.
Reporting immediately ensures organizational response protocols and communication channels are activated.
3
Isolate the system
The machine is quarantined from the network.
Isolating the system contains the threat and prevents the ransomware from spreading to shared files or other machines.
4
Preserve evidence and document chain of custody
Volatile memory and logs are secured with handler details recorded.
Preserving evidence maintains data integrity and ensures forensic evidence remains admissible and verifiable.

Anahtar Kavram

First Responder Incident Response Sequence
Soru 1770Soru

A technician is preparing to open a desktop PC case to replace a failed RAM module. Which TWO of the following actions should the technician perform prior to handling internal components to ensure personal safety and prevent Electrostatic Discharge (ESD) damage? (Select TWO)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Disconnect the AC power cord from the wall outlet or power supply.; Attach an anti-static wrist strap to an unpainted metal surface of the computer chassis.

Cevap

The technician should disconnect the AC power cord from the power supply or outlet and attach an anti-static wrist strap to an unpainted metal portion of the computer frame.
Disconnecting the AC power cord ensures electrical safety by cutting off live electrical current. Attaching an anti-static wrist strap to an unpainted metal chassis surface equalizes static electrical charge between the technician's body and the hardware, preventing ESD from damaging sensitive memory modules.

Adım Adım Çözüm

1
Ensure physical electrical safety
Removing the AC power cord eliminates active electrical potential and prevents shock hazards while working inside the case.
Safety procedures mandate completely disconnecting power before touching internal hardware.
2
Implement ESD mitigation controls
Clipping an ESD wrist strap onto an unpainted metal surface grounds the technician to the computer chassis, equalizing electrical charges.
Sensitive components like RAM modules are highly vulnerable to damage from low-voltage ESD transfers.

Anahtar Kavram

Basic Electrostatic Discharge (ESD) Prevention and Workstation Electrical Safety
Tahmini Süre:45s
Soru 1771Soru

A helpdesk technician needs to create a simple script that executes native Windows Command Prompt (cmd.exe) commands to automate workstation login tasks. Which file extension should be assigned to this script?

Cevabı ve açıklamayı göster

Cevap: .bat

Cevap

The .bat extension is used for standard Windows Batch scripts running in the Command Prompt (cmd.exe).
The .bat extension designates a batch file composed of sequential command-line directives designed to be parsed natively by the Windows Command Prompt (cmd.exe).

Adım Adım Çözüm

1
Identify the target command environment specified in the scenario.
The scenario requires executing native Windows Command Prompt (cmd.exe) commands.
Script file extensions dictate which interpreter or execution host Windows uses to run the file.
2
Match the Windows Command Prompt environment to its proper file extension.
Windows batch files use the .bat file extension.
The Windows Command Prompt natively interprets and executes files saved with the .bat (or legacy .cmd) extension.

Anahtar Kavram

Scripting File Extensions and Runtimes
Soru 1772Soru

A warehouse quality inspector uses a custom Android-based handheld inventory device. During daily auditing, the proprietary scanning application frequently becomes unresponsive and stops syncing data, although all other system applications and wireless connections continue to operate normally. Following standard least-invasive troubleshooting methodology, which TWO of the following initial actions should the technician perform to resolve the issue?

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Force stop the inventory application through the mobile OS application settings; Clear the application's temporary cache memory

Cevap

The technician should force stop the unresponsive application and clear the application cache.
Force stopping an unresponsive app and clearing its cached memory represent the initial, least-invasive troubleshooting steps for isolated mobile application performance issues. These steps terminate hung threads and remove potentially corrupted temporary files without resetting the OS or deleting persistent app data.

Adım Adım Çözüm

1
Isolate the issue scope
Since only the custom scanning application is unresponsive while system connectivity and other apps function normally, the problem is isolated to that specific application process.
Symptom isolation prevents unnecessary global system changes.
2
Apply least-invasive application recovery steps
Force stopping the application terminates hanging process threads, while clearing the app cache removes transient data that may cause application lockups.
Targeted process termination and cache clearing resolve application freezes without data loss.

Anahtar Kavram

Least-Invasive Mobile Application Troubleshooting Sequence
Soru 1773Soru

A tier-2 help desk technician is investigating an enterprise Windows 11 workstation where all installed web browsers (Edge and Chrome) continuously redirect users to an unauthorized site asking for corporate domain credentials when accessing internal or external web applications. The technician observed the following diagnostic details:

- Resetting browser settings, clearing cache/cookies, and starting browsers in safe mode with extensions disabled failed to resolve the issue.
- Automated antivirus and malware scans completed with zero infections detected.
- Standard `ping` requests to domain names resolve to incorrect public IP addresses, even though `ipconfig /all` displays valid corporate internal DNS server IP addresses.
- Running `nslookup company.com` uses the default corporate server and returns the legitimate internal IP address, but browsing directly to `https://company.com` still redirects to the rogue website.

Which of the following root causes is most likely responsible for overriding standard DNS resolution and causing the web browser redirections?

Cevabı ve açıklamayı göster

Cevap: Unauthorized static mapping entries configured inside the local operating system hosts file

Cevap

Unauthorized static mapping entries configured inside the local operating system hosts file
The correct answer identifies unauthorized static mapping entries in the local operating system hosts file (`C:\Windows\System32\drivers\etc\hosts`). Windows evaluates the local `hosts` file prior to sending a query to configured DNS servers. In contrast, the command-line utility `nslookup` directly queries the DNS server, bypassing the local `hosts` file entirely. When `nslookup` yields correct IP addresses while browsers and `ping` commands resolve to malicious IP addresses, it indicates that static entries in the `hosts` file are intercepting and redirecting host name resolution.

Adım Adım Çözüm

1
Analyze name resolution behavior differences between browser requests/ping and `nslookup`.
Identified that `ping` and web browsers use the standard Windows Name Resolution order (which checks the local `hosts` file before querying DNS), whereas `nslookup` queries the configured DNS server directly by design.
When `nslookup` returns the correct IP but browsers resolve to a rogue IP, the discrepancy points to a local override mechanism that precedes DNS server resolution in the OS lookup stack.
2
Evaluate local system components capable of overriding DNS name resolution.
The Windows `hosts` file located at `C:\Windows\System32\drivers\etc\hosts` maps hostnames directly to IP addresses and is evaluated before network DNS queries.
Malware or unauthorized scripts frequently modify the `hosts` file to redirect web requests away from legitimate servers to attacker-controlled IP addresses.
3
Formulate remediation steps.
Inspect and clean the `hosts` file by removing unauthorized static IP-to-hostname mappings.
Clearing malicious lines from the `hosts` file restores standard DNS lookup ordering and stops browser redirects.

Anahtar Kavram

Browser Redirect Troubleshooting and Windows Name Resolution Hierarchy
Soru 1774Soru

An IT technician is dispatched to perform hardware maintenance on a commercial high-volume laser printer that recently experienced a major internal toner spill and high-voltage power fault. Which TWO of the following safety and environmental procedures must the technician implement to safely complete this repair?

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Allow the printer's fuser assembly to cool down fully prior to handling internal components to prevent severe thermal burns.; Use a specialized electrostatic-discharge (ESD) safe vacuum equipped with a fine particulate HEPA filter rather than a standard vacuum cleaner to clean toner dust.

Cevap

The technician must allow the printer's fuser assembly to cool down completely before touch or removal to avoid thermal burn injuries, and use a dedicated ESD-safe toner vacuum with HEPA filtration to clean spilled toner particles safely.
Laser printer maintenance presents specific physical hazards: fuser units reach extreme temperatures requiring time to cool to prevent thermal burns, while spilled toner consists of ultrafine conductive particles that require specialized ESD-safe vacuums with HEPA filters to avoid airborne dispersion, static ignition, and hardware damage.

Adım Adım Çözüm

1
Identify high-temperature hardware components before touching internal printer assemblies.
Recognized that the fuser unit maintains extreme thermal energy and requires cooling down time to ensure technician safety.
Prevent severe skin burns from components operating above 200°C.
2
Evaluate proper cleanup tools for microscopic toner powder.
Selected an ESD-safe vacuum featuring HEPA filters designed specifically for toner dust.
Standard vacuums create static electricity that can ignite toner dust clouds and blow fine toxic particulates back into the breathing environment.
3
Review proper disposal and ESD grounding safety protocols.
Rejected unsafe grounding practices to live AC lines and illegal incineration procedures for chemical waste.
Ensures adherence to CompTIA A+ environmental guidelines and personal electrical safety.

Anahtar Kavram

Laser Printer Thermal and Environmental Safety Practices
Soru 1775Soru

A system administrator resolves an issue where workstations in a remote branch office were failing to obtain authentications from a newly migrated domain controller due to misconfigured subnets in Active Directory Sites and Services. After correcting the site bindings and verifying connectivity, the administrator must complete the ticket lifecycle. Which of the following documentation actions are required before closing the support ticket? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Log the specific root cause, network configuration changes made, and verification test results in the ticket's internal resolution notes.; Update the Configuration Management Database (CMDB) to associate the updated domain controller subnet mappings with the remote branch site asset records.

Cevap

Proper ticketing workflow requires logging the complete technical resolution notes (including root cause and verification steps) and updating infrastructure dependencies in the CMDB before obtaining user sign-off and closing the ticket.
Correct ticket workflow standards dictate that technicians log comprehensive resolution entries (including the root cause, steps taken, and confirmation testing) and update associated asset management database (CMDB) records to reflect configuration updates.

Adım Adım Çözüm

1
Analyze technical documentation requirements for ticketing lifecycle completion.
Identified that comprehensive work logs (root cause, remediation steps, verification) are mandatory for resolution logging.
Capturing full technical details prevents duplicate effort on recurring issues and maintains an accurate audit trail.
2
Evaluate asset management and CMDB workflow integration.
Identified that site subnet reassignments must reflect in the asset management database attached to the ticket.
Maintaining synchronized CMDB infrastructure records ensures operational documentation reflects current environment configurations.
3
Identify improper ticketing procedures in distractors.
Rejected options that overwrite original user input or bypass end-user confirmation prior to closure.
Preserving the original submission preserves audit integrity, and user confirmation verifies actual issue resolution.

Anahtar Kavram

Complete Incident Documentation and Ticket Resolution Workflows
Soru 1776Soru

A tier-2 systems technician is configuring network access and security rules for an administrator who needs to perform secure, encrypted command-line management on a remote Linux server located behind a corporate firewall. Which of the following protocols and standard transport layer port numbers must be enabled on the firewall to allow this access? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: SSH (Secure Shell); TCP port 22

Cevap

The correct selections are SSH (Secure Shell) and TCP port 22.
SSH (Secure Shell) combined with TCP port 22 satisfies both requirements: establishing an encrypted command-line connection to a remote server and permitting the necessary network traffic through the perimeter firewall.

Adım Adım Çözüm

1
Identify the remote access interface requirement
The scenario calls for a secure, encrypted text-based command-line interface to manage a Linux server.
Linux administration typically relies on command-line utilities, which must be encrypted when accessed across external networks.
2
Select the appropriate remote access protocol
SSH (Secure Shell) is selected over Telnet because Telnet transmits data in plain text without encryption.
SSH encrypts all traffic, including authentication credentials and terminal output.
3
Identify the default TCP port for the chosen protocol
SSH operates over TCP port 22 by default.
Firewall rules must permit inbound traffic on TCP port 22 to allow the SSH daemon on the target server to accept connections.

Anahtar Kavram

Remote Command-Line Security Protocols and Default Ports
Soru 1777Soru

A remote desktop technician is connected to an end user's system via an authorized screen-sharing session to troubleshoot an email profile error. During the session, the user receives an urgent phone call and steps away from their desk, leaving a sensitive spreadsheet containing unencrypted Personally Identifiable Information (PII) open on the display. Which of the following actions should the technician take to uphold data privacy and professional communication standards? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Refrain from inspecting, copying, or altering the sensitive file visible on the display.; Pause the remote control session stream until the user returns to their workstation.

Cevap

The technician should refrain from inspecting, copying, or altering sensitive files on display, and pause the remote control session stream until the user returns.
When sensitive or confidential information is exposed during a support session, professional guidelines dictate respecting customer privacy by avoiding any inspection or alteration of the data, and pausing active remote viewing streams until the user returns to control their environment.

Adım Adım Çözüm

1
Assess the remote environment upon the user stepping away.
Identify that confidential data (PII) is exposed on the unattended remote screen.
Technicians must constantly maintain awareness of customer privacy and security boundaries during remote sessions.
2
Protect user privacy by restricting unauthorized viewing and interaction.
Pause the remote control stream and avoid reading, copying, or changing the open file.
Pausing remote viewing prevents unauthorized exposure of data, while avoiding file interaction preserves data integrity and respects user property.

Anahtar Kavram

Customer Privacy and Ethical Boundaries in Remote Sessions
Soru 1778Soru

A desktop technician is troubleshooting a Windows workstation displaying missing file errors and system instability. The technician suspects corruption within both the Windows component store and protected operating system files. In what order should the technician perform the following repair steps to ensure system integrity is fully restored?

Öğeleri doğru sıraya koymak için sürükleyin

Cevabı ve açıklamayı göster

Cevap

The correct sequence of repair steps is: Open an elevated Command Prompt, execute DISM to repair the component store, execute SFC to repair system files, and restart the computer to complete pending replacements.
To repair corrupted operating system files effectively, administrative elevation must be established first. Executing DISM `/restorehealth` restores the health of the Windows component store image. Once the store is repaired, running `sfc /scannow` allows the System File Checker to successfully extract clean file copies from the component store and repair corrupted OS files. Finally, restarting the workstation applies file updates for core binaries that were locked in active memory during the scan.

Adım Adım Çözüm

1
Open Command Prompt with administrative privileges.
Obtains necessary administrative permissions to run system-level diagnostic and repair tools.
Both DISM and SFC require elevated privilege levels to modify protected system directories.
2
Run `dism /online /cleanup-image /restorehealth`.
Scans and repairs the Windows image component store cache.
The System File Checker uses the component store as its source repository. If the component store itself is corrupt, SFC will fail to repair files until DISM fixes the store.
3
Run `sfc /scannow`.
Scans protected system files and replaces corrupted ones using the restored component store.
Once the component store is healthy, SFC can pull clean replacement files to replace damaged system binaries.
4
Reboot the operating system.
Applies changes to system files that could not be modified while actively loaded in memory.
Core operating system files in active use are queued for replacement during the next system startup.

Anahtar Kavram

Sequential repair of Windows component store using DISM prior to executing System File Checker (SFC)
Tahmini Süre:1m 30s
Soru 1779Soru

A field technician is called to secure a finance manager's workstation that was infected with ransomware via a suspicious email link. The technician immediately isolates the workstation from the corporate network and captures a forensic image of volatile memory. To ensure all evidence remains legally admissible, the technician prepares to transfer the physical workstation to the enterprise forensics team. Which of the following details MUST be documented on the chain of custody form during this transfer?

Cevabı ve açıklamayı göster

Cevap: The date, time, unique device serial numbers, and the signatures of both the transferring technician and receiving investigator

Cevap

The date, time, unique device serial numbers, and the signatures of both the transferring technician and receiving investigator must be documented on the chain of custody form during the transfer.
Chain of custody documentation provides an unbroken chronological record tracking the acquisition, transfer, analysis, and disposition of physical and digital evidence. Whenever evidence changes hands, the log must capture the date, time, exact item description and serial number, location, and the verified signatures of both the individual surrendering the evidence and the individual receiving it.

Adım Adım Çözüm

1
Identify the core purpose of chain of custody documentation in forensic procedures.
Chain of custody establishes a continuous, legally defensible audit trail showing who possessed, secured, or transferred physical and digital evidence at every point in time.
If custody cannot be proven unbroken, evidence may be deemed tampered with or inadmissible in legal proceedings.
2
Identify mandatory fields required during an evidence custody transfer.
The log must record the precise date and time of transfer, detailed description and serial numbers of the item, location details, and the full names and signatures of both the releasing party and receiving party.
This establishes clear responsibility and accountability for the evidence at the exact moment of transfer.
3
Evaluate the choices against chain of custody logging standards.
Recording timestamps, hardware identifiers, and signatures of both parties satisfies the formal chain of custody requirements.
Passwords, building physical barrier specifications, and malware classification taxonomies do not fulfill evidence tracking requirements.

Anahtar Kavram

Chain of Custody Documentation Requirements
Soru 1780Soru

An employee reports that their corporate-managed smartphone suddenly cannot access internal enterprise email servers while connected to cellular data, though public websites load without issue. A technician verifies that the cellular carrier network is fully operational. Which of the following is the most likely cause of this access restriction?

Cevabı ve açıklamayı göster

Cevap: An expired or corrupted enterprise MDM security profile on the device

Cevap

An expired or corrupted enterprise MDM security profile on the device
Mobile Device Management (MDM) security profiles enforce access rules and store identity certificates required to authenticate to enterprise email servers. If the profile expires or becomes corrupted, the device is restricted from corporate resources, even though general internet connectivity over cellular data remains functional.

Adım Adım Çözüm

1
Analyze the reported symptoms and network scope
General internet traffic functions normally over cellular data, but access to internal enterprise email resources is blocked.
Determining whether connectivity issues affect all network traffic or only corporate services isolates device security profile issues from carrier outages.
2
Evaluate potential root causes specific to enterprise service access
Corporate email authentication relies on valid Mobile Device Management (MDM) configuration profiles and security certificates.
If an MDM profile expires or becomes corrupted, corporate access control policies block access to enterprise resources.

Anahtar Kavram

Troubleshooting Mobile OS MDM Security Profiles and Corporate Resource Connectivity
Tahmini Süre:1m 0s
ÖncekiSayfa 89 / 178Sonraki
Tüm alıştırma soruları — CompTIA A+ (Core 1 & Core 2) | Examkin