CompTIA A+ 220-1102 Practice Test Questions and Exam Dumps Part7 Q121-140

View Full CompTIA A+ 220-1102 Exam Dumps and Practice Test Dumps

 

Question 121.

A Windows 11 user reports that files on a shared folder are accessible to everyone in the department, but one user should only be able to read the files and must not modify them. Which security control should the technician configure?

  1. File and folder permissions
    2. BitLocker
    3. Windows Update
    4. Disk Cleanup

Correct Answer: 1

Explanation:

File and folder permissions are used to control what users and groups can do with data. A technician can grant the affected user read access while withholding permissions such as Modify, Write, or Full Control. This follows the principle of least privilege because the user receives only the access needed to perform the assigned job. BitLocker encrypts a volume and primarily protects data at rest; it does not provide the same granular per-user access model for shared files. Windows Update handles operating-system updates, while Disk Cleanup removes unnecessary files. When a problem concerns who can read, modify, or delete specific folders, permissions are the most directly relevant security control.

Question 122.

Which Windows permission generally allows a user to read, create, modify, and delete files and folders without granting complete control over permissions and ownership?

  1. Read
    2. Modify
    3. List Folder Contents
    4. Special Permissions only

Correct Answer: 2

Explanation:

The Modify permission typically allows users to read, create, change, and delete files and folders while not necessarily granting the broader administrative capabilities associated with Full Control. It is often appropriate for users who need to actively work with data but should not be able to change permissions or take ownership. Read permission is much more limited, while List Folder Contents primarily allows viewing folder contents. Special Permissions represent more granular combinations that can be customized for specific needs. Technicians should grant the minimum access necessary and remember that effective access can result from multiple user and group memberships.

Question 123.

A technician needs to determine the effective NTFS access a user receives from several group memberships. Which principle should the technician remember?

  1. Only the first group membership is evaluated
    2. Permissions never combine
    3. Effective access can result from combined permissions, while explicit deny entries can override allowed access in many cases
    4. NTFS permissions apply only to removable drives

Correct Answer: 3

Explanation:

A user can inherit permissions from several group memberships, and allowed permissions are generally cumulative. For example, if one group grants Read and another grants Modify, the user may effectively receive the broader combined access. Deny entries must be considered carefully because they can override allowed permissions in many common scenarios. This is why technicians should review effective access rather than looking at only one group. NTFS permissions are not limited to removable media; they are commonly used on Windows volumes and shared folders. Proper permission design is easier to manage when access is assigned to groups rather than individually to many users.

Question 124.

Which Windows technology should be used when an organization wants to encrypt an entire laptop system drive to protect data if the laptop is stolen?

  1. EFS
    2. Windows Firewall
    3. System Restore
    4. BitLocker

Correct Answer: 4

Explanation:

BitLocker provides full-volume encryption and is well suited to protecting laptops and other systems against offline access if the device is lost or stolen. It can work with TPM hardware and additional authentication methods depending on organizational policy. EFS is designed primarily for file- and folder-level encryption rather than full-volume protection. Windows Firewall controls network traffic, and System Restore rolls back selected system configuration changes. Organizations using BitLocker should also securely manage recovery keys because they may be needed when TPM validation fails, hardware changes occur, or a user cannot complete normal startup authentication. Encryption protects confidentiality but should still be combined with account security and physical controls.

Question 125.

A user encrypted several NTFS files with EFS and later lost access to the original Windows profile and private key. What is the primary concern?

  1. The files may be unrecoverable without the required encryption certificate or recovery mechanism
    2. Windows will automatically decrypt every file
    3. EFS converts the files to FAT32
    4. The files will automatically move to OneDrive

Correct Answer: 1

Explanation:

EFS encryption depends on cryptographic keys and certificates associated with the authorized user or a configured recovery mechanism. If those keys are lost and there is no recovery certificate or backup of the encryption material, the files may become inaccessible even though the data itself remains on the disk. This is why encryption key management and recovery planning are essential. EFS does not convert files to another file system, and Windows does not automatically remove encryption merely because a profile is damaged. The files also do not move to cloud storage automatically. Encryption provides strong confidentiality, but poor key management can create a serious availability problem for legitimate users.

Question 126.

Which Windows feature is designed to isolate an untrusted application in a temporary environment that is discarded after use?

  1. Disk Management
    2. Windows Sandbox
    3. File History
    4. Services

Correct Answer: 2

Explanation:

Windows Sandbox provides a lightweight, temporary Windows environment that can be used to run potentially untrusted software separately from the main operating system. When the sandbox is closed, the temporary environment and its changes are discarded. This makes it useful for safely examining unknown applications or testing software without permanently altering the host. It is not a substitute for comprehensive malware analysis or endpoint security, but it adds isolation for common testing scenarios. Disk Management handles partitions, File History protects user files, and Services controls background services. Technicians should still avoid executing obviously malicious software on production systems even inside isolation technologies unless organizational procedures permit it.

Question 127.

Which security feature helps verify that trusted boot components are loaded before Windows starts?

  1. File History
    2. Password history
    3. Secure Boot
    4. Disk Cleanup

Correct Answer: 3

Explanation:

Secure Boot is a UEFI security capability designed to help ensure that trusted, digitally signed boot components are loaded during system startup. This helps protect against certain bootkits and other forms of malware that attempt to compromise a computer before the operating system and endpoint protections are fully active. File History protects versions of user data, password history prevents reuse of recently used passwords, and Disk Cleanup removes unnecessary files. Secure Boot works as part of the platform’s trusted startup process and complements technologies such as TPM, BitLocker, firmware security, and modern operating-system protections.

Question 128.

A company wants to prevent employees from installing unauthorized applications on managed Windows computers. Which security approach is most appropriate?

  1. Give every employee local administrator access
    2. Disable all authentication prompts
    3. Share one administrator password with the department
    4. Use least privilege and application-control policies

Correct Answer: 4

Explanation:

Least privilege and application-control policies reduce the ability of users to install unauthorized or potentially dangerous software. Standard users should normally perform daily work without local administrator rights, while approved administrative tasks can be handled through controlled elevation. Application-control technologies can further restrict which software is permitted to run. Giving every employee administrator access dramatically increases risk because malware and users can make system-wide changes more easily. Shared administrator passwords also weaken accountability and increase exposure. A strong design combines least privilege, software restrictions, secure deployment procedures, endpoint protection, and monitoring rather than relying on user discretion alone.

Question 129.

Which account-management practice is most appropriate when an employee leaves the company?

  1. Disable or remove access according to the organization’s offboarding process
    2. Keep the account active indefinitely
    3. Give the credentials to the replacement employee
    4. Rename the account but keep the same password

Correct Answer: 1

Explanation:

When an employee leaves an organization, access should be disabled or removed according to established offboarding procedures. This can include disabling directory accounts, revoking remote access, removing application access, retrieving company devices, and addressing security tokens or keys. Former employee credentials should not be transferred to another worker because this breaks accountability and may expose sensitive resources. Simply renaming an account or keeping it active also preserves unnecessary risk. Timely account deprovisioning is an important part of identity and access management and should be coordinated with human resources, management, and security procedures.

Question 130.

Which policy helps prevent unauthorized password guessing by locking an account after a specified number of failed login attempts?

  1. File retention policy
    2. Account lockout policy
    3. Backup rotation policy
    4. Screen resolution policy

Correct Answer: 2

Explanation:

An account lockout policy temporarily disables an account after a configured number of failed login attempts. This makes repeated online password guessing more difficult because an attacker cannot indefinitely try candidate passwords against the same account. The threshold, lockout duration, and reset timing should be selected carefully because overly aggressive settings can allow attackers to deliberately lock legitimate users out. Account lockout is only one authentication control and works best alongside long passwords, multifactor authentication, monitoring, and user education. File retention, backup rotation, and display settings do not directly control failed authentication attempts.

Question 131.

Which Windows utility should a technician use to configure local password and account policies on a supported standalone Windows system?

  1. Disk Cleanup
    2. Device Manager
    3. Local Security Policy
    4. File Explorer

Correct Answer: 3

Explanation:

Local Security Policy provides access to security-related settings on supported Windows editions, including account policies, local policies, audit settings, user rights assignments, and certain security options. A technician can use it to configure password requirements, account lockout settings, and other local security behavior when a computer is not being centrally managed through domain Group Policy. Disk Cleanup removes temporary files, Device Manager handles hardware and drivers, and File Explorer manages files and folders. In centrally managed environments, domain-based policy may override local settings, so technicians should understand the management context before making local changes.

Question 132.

A technician needs to identify whether a user is a member of the local Administrators group. Which Windows utility can be used to manage local users and groups on supported editions?

  1. Task Scheduler
    2. Disk Management
    3. Reliability Monitor
    4. Local Users and Groups

Correct Answer: 4

Explanation:

Local Users and Groups allows administrators on supported Windows editions to manage local accounts and group memberships. A technician can inspect whether a user belongs to groups such as Administrators or Users and can add or remove memberships when authorized. Membership in the Administrators group provides elevated capabilities and should therefore be granted only when required. Task Scheduler automates actions, Disk Management handles storage, and Reliability Monitor summarizes system stability. In domain-managed environments, many identities and permissions may instead be controlled centrally, but local group membership still remains an important troubleshooting and security consideration.

Question 133.

A workstation repeatedly displays browser pop-ups and redirects searches to unknown websites. Which type of unwanted software is a likely cause?

  1. Adware
    2. Logic bomb
    3. Boot manager
    4. Hypervisor

Correct Answer: 1

Explanation:

Adware commonly causes unwanted advertisements, browser pop-ups, search redirects, injected content, and potentially unwanted browser extensions. While some ad-supported software is technically legitimate, aggressive or deceptive adware can create security and privacy concerns. A logic bomb activates malicious behavior when a specific condition occurs, while a boot manager and hypervisor are legitimate system technologies. The technician should inspect installed applications and browser extensions, update endpoint protection, run appropriate scans, and remove unwanted components. The system should also be patched and the user educated about avoiding suspicious software bundles and installation prompts.

Question 134.

A malicious program records websites visited, credentials entered, and other user activity without authorization. What type of malware is this?

  1. Worm
    2. Spyware
    3. Ransomware
    4. Root certificate

Correct Answer: 2

Explanation:

Spyware is designed to secretly collect information about a user or computer. It may track browsing habits, capture credentials, record system information, monitor communications, or send collected data to an attacker. Some spyware can be combined with keylogging or browser hijacking features. A worm focuses primarily on self-propagation, ransomware restricts access to systems or files, and a root certificate is a legitimate cryptographic concept rather than a malware category by itself. Suspected spyware should be handled through the organization’s malware-removal and incident-response process, including isolation, scanning, remediation, patching, and verification.

Question 135.

A malicious program encrypts local and network files and demands cryptocurrency for a decryption key. Which threat is being described?

  1. Adware
    2. Spyware
    3. Ransomware
    4. Tailgating

Correct Answer: 3

Explanation:

Ransomware commonly encrypts data or otherwise prevents access to systems and then demands payment in exchange for restoration. Modern ransomware may also steal information before encryption and threaten public disclosure, increasing pressure on victims. Tailgating is a physical access attack, while spyware gathers information and adware displays unwanted advertisements. Defenses include patching, endpoint protection, least privilege, network segmentation, multifactor authentication, restricted administrative access, and tested backups that are protected from the same compromise. If ransomware is detected, rapid isolation and incident-response procedures are important to reduce further spread and damage.

Question 136.

A user receives a phone call from someone claiming to be technical support and asking for a one-time MFA code. Which type of attack is this?

  1. Shoulder surfing
    2. Tailgating
    3. Smishing
    4. Vishing

Correct Answer: 4

Explanation:

Vishing is phishing conducted through voice calls. Attackers often impersonate technical support, banks, government agencies, or other trusted organizations and attempt to convince victims to reveal passwords, multifactor authentication codes, or financial information. An MFA code should be treated as sensitive authentication data and should not be shared with an unsolicited caller. Smishing uses text messages, shoulder surfing involves observing someone physically, and tailgating involves following an authorized person into a restricted location. Users should independently verify suspicious callers using a trusted contact method and report the attempted attack according to organizational procedures.

Question 137.

Which social-engineering attack involves sending fraudulent SMS messages containing malicious links or requests for credentials?

  1. Smishing
    2. Vishing
    3. Whaling only
    4. Tailgating

Correct Answer: 1

Explanation:

Smishing is phishing performed through SMS or similar text messaging channels. Attackers may claim there is a problem with a bank account, package delivery, tax payment, employee account, or other urgent situation and encourage the victim to click a malicious link. The link may lead to credential theft, malware, or financial fraud. Vishing uses voice calls, whaling is targeted phishing aimed at high-value individuals, and tailgating is a physical access technique. Users should avoid opening suspicious links and instead access legitimate services through known applications or independently verified websites.

Question 138.

Which physical security device is most appropriate for reducing unauthorized viewing of sensitive information on a laptop screen in a public location?

  1. Cable lock
    2. Privacy filter
    3. Biometric reader
    4. UPS

Correct Answer: 2

Explanation:

A privacy filter restricts the viewing angle of a display so that the screen is difficult to read from the side. This helps reduce shoulder-surfing risk when users work in airports, coffee shops, trains, open offices, or other public environments. A cable lock helps prevent theft of the physical device, a biometric reader supports authentication, and a UPS provides power protection. Privacy filters are most effective when combined with user awareness, screen locking, careful seating position, and avoiding unnecessary display of confidential information in public. Physical confidentiality controls are an important complement to technical access controls.

Question 139.

Which physical security control records activity around entrances and equipment rooms and can assist with investigations after an incident?

  1. Password complexity
    2. BitLocker
    3. Surveillance camera
    4. NTFS permission

Correct Answer: 3

Explanation:

Surveillance cameras provide visual monitoring and recorded evidence of activity in sensitive locations such as building entrances, server rooms, storage areas, and data centers. Cameras can deter unauthorized behavior and help investigators reconstruct events after theft, unauthorized entry, or other incidents. Password complexity, BitLocker, and NTFS permissions are logical controls that protect digital resources rather than monitor physical spaces. Cameras should normally be combined with access badges, locks, visitor procedures, alarms, and appropriate monitoring. Organizations should also follow legal and privacy requirements governing video surveillance and retention.

Question 140.

A technician finishes removing malware, installs updates, verifies that endpoint protection is active, and confirms that the workstation works normally. What should be done before the incident is closed?

  1. Disable the firewall to improve performance
    2. Remove all user passwords
    3. Delete the support history
    4. Document the symptoms, actions taken, results, and any preventive measures

Correct Answer: 4

Explanation:

After the threat has been removed and normal system functionality has been verified, the technician should document the incident thoroughly. Documentation should include the original symptoms, suspected or confirmed cause, containment steps, tools used, remediation actions, updates performed, validation results, and preventive recommendations. This creates a useful support record and can help the organization detect recurring security problems. Disabling the firewall or removing passwords would weaken security, while deleting the support history would reduce accountability and organizational knowledge. Documentation is the final stage of the troubleshooting process and is especially important in malware incidents because lessons learned can help prevent future compromise.