CompTIA A+ 220-1102 Practice Test Questions and Exam Dumps Part4 Q61-80

View Full CompTIA A+ 220-1102 Exam Dumps and Practice Test Dumps

 

Question 61.

A Windows user reports that a workstation has become unusually slow after many applications were installed and removed. Which built-in utility can help identify which applications and services are consuming the most CPU and memory in real time?

  1. Task Manager
    2. Disk Management
    3. File Explorer Options
    4. System Restore

Correct Answer: 1

Explanation:

Task Manager provides real-time information about running processes and their use of CPU, memory, disk, network, and other resources. A technician can sort processes by resource consumption to identify applications or background services that may be causing poor performance. Disk Management is intended for disks and partitions, File Explorer Options controls file and folder display behavior, and System Restore rolls back certain system changes. When troubleshooting a slow Windows computer, Task Manager is often one of the fastest ways to determine whether a particular process is consuming excessive system resources.

Question 62.

Which Windows utility can help a technician determine which applications are configured to launch automatically when a user signs in?

  1. Event Viewer
    2. Task Manager
    3. Device Manager
    4. Disk Cleanup

Correct Answer: 2

Explanation:

Task Manager includes a Startup section that lists many applications configured to start automatically when Windows loads or when the user signs in. A technician can review startup impact and disable unnecessary items to improve startup performance. Event Viewer displays system and application logs, Device Manager handles hardware and drivers, and Disk Cleanup removes unnecessary files. Disabling an unnecessary startup application does not normally uninstall it; it simply prevents the program from launching automatically. This makes Task Manager a useful tool when excessive startup applications are causing long boot or sign-in times.

Question 63.

A Windows service fails every time the computer starts. Which tool should a technician use to review related system and application error messages?

  1. Disk Management
    2. File History
    3. Event Viewer
    4. Windows Sandbox

Correct Answer: 3

Explanation:

Event Viewer stores detailed Windows logs that can help diagnose service failures, application crashes, driver problems, authentication events, and many other operating-system issues. A technician can examine System and Application logs around the time of the failure and look for event IDs, sources, and descriptive messages. Disk Management handles storage volumes, File History protects user files, and Windows Sandbox provides a temporary isolated Windows environment. Event Viewer is especially valuable for recurring or intermittent problems because it provides a historical record that can be correlated with the reported symptoms.

Question 64.

Which Windows utility allows a technician to configure whether a service starts automatically, manually, or is disabled?

  1. Reliability Monitor
    2. Task Scheduler
    3. Device Manager
    4. Services

Correct Answer: 4

Explanation:

The Services management console allows technicians to view Windows services, start or stop them, and configure startup types such as Automatic, Manual, and Disabled. This is useful when troubleshooting applications or operating-system functions that depend on a particular background service. Reliability Monitor summarizes system stability events, Task Scheduler automates tasks, and Device Manager manages hardware devices. Because disabling the wrong service can affect Windows functionality, technicians should understand the service’s purpose and dependencies before changing its startup configuration.

Question 65.

Which Windows command should a technician use to release the current DHCP-assigned IPv4 address on a workstation?

  1. ipconfig /release
    2. ipconfig /flushdns
    3. ping -t
    4. netstat -r

Correct Answer: 1

Explanation:

The ipconfig /release command releases the current DHCP lease for applicable network adapters. It is commonly followed by ipconfig /renew when a technician wants the workstation to request a fresh IP configuration from a DHCP server. This can help troubleshoot incorrect or stale DHCP assignments. ipconfig /flushdns clears the local DNS resolver cache, ping -t continuously sends ping requests until stopped, and netstat -r displays routing information. Releasing and renewing a DHCP address is useful when the problem concerns dynamically assigned network configuration rather than DNS resolution.

Question 66.

Which Windows command should be used after releasing a DHCP lease to request a new IP address from a DHCP server?

  1. nslookup
    2. ipconfig /renew
    3. tracert
    4. hostname

Correct Answer: 2

Explanation:

The ipconfig /renew command requests a new DHCP lease for applicable Windows network adapters. It is often used after ipconfig /release when troubleshooting connectivity or an incorrect DHCP configuration. A successful renewal can provide a valid IP address, subnet mask, default gateway, and other DHCP-supplied information. nslookup is used for DNS troubleshooting, tracert displays the route toward a remote host, and hostname identifies the local computer. If renewal fails, the technician should investigate network connectivity, DHCP availability, adapter status, and VLAN or switch configuration.

Question 67.

A workstation can communicate with devices by IP address but cannot access them by hostname. Which issue should the technician investigate first?

  1. Disk fragmentation
    2. NTFS permissions
    3. DNS configuration
    4. BitLocker recovery

Correct Answer: 3

Explanation:

If a system can reach another host by IP address but not by hostname, basic IP connectivity is working and name resolution is the more likely problem. The technician should review the configured DNS servers and use tools such as nslookup or ipconfig /all to verify DNS settings. Disk fragmentation does not cause hostname-resolution failures, NTFS permissions concern file access, and BitLocker protects encrypted drives. Troubleshooting by separating connectivity from name resolution helps narrow the problem quickly and avoids making unrelated changes to the workstation.

Question 68.

Which Windows command clears locally cached DNS records?

  1. ipconfig /release
    2. net use
    3. gpupdate
    4. ipconfig /flushdns

Correct Answer: 4

Explanation:

The ipconfig /flushdns command clears the Windows DNS resolver cache. This is useful when the local computer has cached an outdated or incorrect DNS record after a server address has changed. The command does not change the workstation’s DNS server configuration; it simply removes cached name-resolution entries so subsequent requests must be resolved again. ipconfig /release releases a DHCP address, net use manages network shares, and gpupdate refreshes Group Policy. Flushing DNS is therefore appropriate when stale cached records are suspected.

Question 69.

A technician needs to determine which ports a Windows workstation is listening on. Which command is most appropriate?

  1. netstat
    2. gpresult
    3. chkdsk
    4. format

Correct Answer: 1

Explanation:

netstat can display active network connections and listening ports on a Windows computer. With appropriate options, it can also show numerical addresses, process identifiers, and routing information. This makes it useful when troubleshooting whether an application is actually listening on an expected TCP or UDP port or when examining suspicious network activity. gpresult reports Group Policy settings, chkdsk checks file-system integrity, and format prepares a volume. Netstat is therefore one of the primary command-line tools for inspecting local network connections and listeners.

Question 70.

Which Windows command can display the MAC address and detailed TCP/IP settings for each network adapter?

  1. hostname
    2. ipconfig /all
    3. sfc /scannow
    4. taskkill

Correct Answer: 2

Explanation:

The ipconfig /all command displays detailed configuration information for Windows network interfaces. This includes IP addresses, subnet masks, default gateways, DNS servers, DHCP status, lease information, and physical or MAC addresses. It is therefore a useful starting point when diagnosing network configuration problems. hostname only displays the computer’s host name, sfc /scannow checks protected Windows system files, and taskkill terminates processes. When a technician needs a complete view of the workstation’s TCP/IP configuration, ipconfig /all is the most appropriate command.

Question 71.

Which type of malware pretends to be legitimate software while secretly performing malicious activity?

  1. Rootkit
    2. Worm
    3. Trojan
    4. Spam

Correct Answer: 3

Explanation:

A Trojan disguises itself as legitimate or desirable software in order to convince a user to install or execute it. Once running, it may steal data, install additional malware, establish remote access, or perform other unauthorized actions. A worm is designed to spread between systems, often without direct user action. A rootkit attempts to hide malicious activity or provide stealthy privileged access, while spam consists of unsolicited messages. User awareness, application allowlisting, endpoint security, patching, and obtaining software only from trusted sources can reduce the risk of Trojan infections.

Question 72.

Which type of malware can spread automatically between systems without requiring the user to manually copy or launch the malware on each device?

  1. Adware
    2. Trojan
    3. Spyware
    4. Worm

Correct Answer: 4

Explanation:

A worm is self-propagating malware that can spread from one system to another, often by exploiting software vulnerabilities or weak network security. Because worms can spread automatically, they may infect many devices rapidly once introduced into a network. Trojans typically rely on users being tricked into running malicious software, adware displays unwanted advertising, and spyware gathers information about users or systems. Network segmentation, timely patching, endpoint security, firewalls, and monitoring are important controls for reducing the spread and impact of worm-based malware.

Question 73.

Which type of malicious software is primarily designed to secretly collect information about a user’s activity?

  1. Spyware
    2. Logic bomb
    3. Ransomware
    4. Worm

Correct Answer: 1

Explanation:

Spyware is designed to monitor user or system activity and collect information without appropriate authorization. Depending on the malware, it may track browsing activity, capture credentials, collect system information, or send data to an attacker. A logic bomb activates when a specified condition occurs, ransomware denies access to systems or data and often demands payment, and a worm focuses on self-propagation. Endpoint security, software updates, secure browsing practices, least privilege, and user awareness can all help reduce the risk of spyware infections.

Question 74.

A user receives an email that claims to be from the company’s CEO and urgently requests a wire transfer to a new account. Which social-engineering technique is most likely being used?

  1. Tailgating
    2. Whaling
    3. Shoulder surfing
    4. Dumpster diving

Correct Answer: 2

Explanation:

Whaling is a targeted form of phishing focused on executives, senior leaders, or other high-value individuals and communications. Attackers may impersonate senior management and create a sense of urgency to pressure employees into transferring money, sharing credentials, or bypassing normal procedures. Tailgating is a physical access attack, shoulder surfing involves observing sensitive information, and dumpster diving involves searching discarded materials. Organizations can reduce the risk of whaling and business email compromise by requiring independent verification for financial requests and training employees to question unusual or urgent executive messages.

Question 75.

Which physical security control allows only one person at a time to pass through a controlled area using two interlocking doors?

  1. Cable lock
    2. Badge reader only
    3. Mantrap
    4. Privacy screen

Correct Answer: 3

Explanation:

A mantrap is a physical access-control system that typically uses two interlocking doors to control entry into a secure area. A person enters through the first door, undergoes authentication or verification, and can proceed through the second door only after the first is secured. This helps reduce tailgating and unauthorized entry. A cable lock protects equipment from theft, a badge reader authenticates credentials but does not by itself enforce one-person passage, and a privacy screen limits visual observation of a display. Mantraps are commonly used in high-security facilities and sensitive data-center environments.

Question 76.

Which physical security device is primarily intended to prevent a laptop from being easily removed from a desk?

  1. Smart card
    2. Biometric scanner
    3. Privacy filter
    4. Cable lock

Correct Answer: 4

Explanation:

A cable lock physically attaches a laptop or other compatible device to a fixed object, helping deter opportunistic theft. It does not prevent all possible theft attempts, but it adds a physical barrier that can make unauthorized removal more difficult. A smart card and biometric scanner are authentication controls, while a privacy filter reduces visual exposure of information displayed on a screen. Physical device protection is especially important in open offices, classrooms, public spaces, and other environments where portable systems may be left unattended.

Question 77.

Which action is most appropriate if a technician discovers a suspected malware infection on a corporate workstation connected to the network?

  1. Isolate the workstation from the network
    2. Copy suspicious files to every file server
    3. Disable endpoint protection
    4. Continue normal use until the end of the week

Correct Answer: 1

Explanation:

Isolating a suspected infected workstation helps contain the incident by reducing the chance that malware spreads to other systems or communicates with external command-and-control infrastructure. Once isolated, the technician can follow organizational malware-removal and incident-response procedures, update security tools where appropriate, scan the system, remediate the infection, and verify functionality. Disabling endpoint protection or continuing normal use increases risk. Copying suspicious files to shared systems could spread the infection. Containment is therefore a critical early action when dealing with suspected malware.

Question 78.

After removing malware from a user’s computer, which action should a technician perform before returning the workstation to normal use?

  1. Disable Windows Update
    2. Update security software, scan again, and verify system functionality
    3. Remove all passwords
    4. Turn off the firewall permanently

Correct Answer: 2

Explanation:

After malware has been removed, the technician should update the operating system and security tools, perform additional scans as appropriate, verify that security protections are enabled, and confirm that the system functions normally. The underlying vulnerability or unsafe configuration that contributed to the infection should also be addressed where possible. Disabling updates or the firewall would weaken security, while removing passwords would create additional exposure. A system should not be returned to normal use until reasonable verification indicates that the threat has been removed and protective controls are functioning correctly.

Question 79.

Which security concept requires sensitive information to be accessible only to authorized individuals?

  1. Availability
    2. Integrity
    3. Confidentiality
    4. Redundancy

Correct Answer: 3

Explanation:

Confidentiality is the security principle concerned with preventing unauthorized disclosure of information. Controls that support confidentiality include encryption, access permissions, authentication, physical security, and proper data handling. Integrity focuses on preventing unauthorized modification of data, while availability focuses on ensuring that systems and information remain accessible when required. Redundancy can improve availability but is not one of the three core elements of the CIA security triad. Protecting confidential information is especially important for credentials, financial records, customer information, and other sensitive organizational data.

Question 80.

A technician confirms the root cause of a problem and identifies an appropriate fix. According to the CompTIA troubleshooting methodology, what should the technician do next?

  1. Document the findings immediately and close the ticket
    2. Replace all related hardware
    3. Ignore possible side effects
    4. Establish a plan of action to resolve the problem and identify potential effects

Correct Answer: 4

Explanation:

After the probable cause has been established and confirmed, the technician should create a plan of action to resolve the problem and consider any possible effects of the proposed change. This planning step helps reduce the chance that the fix creates additional problems or unnecessary downtime. The technician should then implement the solution, verify full system functionality, implement preventive measures if appropriate, and document findings, actions, and outcomes. Closing the ticket before implementing and verifying the solution would be premature. A structured troubleshooting process improves consistency and reduces avoidable mistakes.