CompTIA A+ 220-1102 Practice Test Questions and Exam Dumps Part8 Q141-160

View Full CompTIA A+ 220-1102 Exam Dumps and Practice Test Dumps

 

Question 141.

A Windows workstation is joined to a company domain. A technician wants to determine which domain policies are currently affecting the user account. Which command is most appropriate?

  1. gpresult
    2. chkdsk
    3. net use
    4. taskkill

Correct Answer: 1

Explanation:

The gpresult command displays information about Group Policy settings that have been applied to the computer and user. This makes it useful when a technician needs to verify whether expected security, desktop, software, or network policies are actually taking effect. Depending on the switches used, gpresult can provide more detailed information about the Resultant Set of Policy. chkdsk checks disks and file-system integrity, net use manages connections to network shares, and taskkill terminates processes. In a domain environment, confirming effective Group Policy is an important troubleshooting step before assuming that a local Windows setting is the cause of the problem.

Question 142.

A technician has just changed a Group Policy setting and wants the workstation to process the new policy immediately. Which command should be used?

  1. sfc /scannow
    2. gpupdate
    3. hostname
    4. arp -a

Correct Answer: 2

Explanation:

The gpupdate command refreshes applicable Group Policy settings for the user and computer. It is often used after a policy has been changed so the administrator does not need to wait for the normal background policy refresh interval. The command can be especially useful during troubleshooting when the technician wants to determine whether a newly configured policy resolves the issue. sfc /scannow checks protected Windows system files, hostname displays the local computer name, and arp -a shows IP-to-MAC mappings in the local ARP cache. gpupdate is specifically intended to refresh Group Policy processing.

Question 143.

A Windows user receives an “Access Denied” message when attempting to open a folder. The user should have access based on job responsibilities. Which item should the technician examine first?

  1. Screen resolution
    2. Power plan
    3. File and folder permissions
    4. DNS suffix

Correct Answer: 3

Explanation:

An “Access Denied” message when opening a local or shared folder strongly suggests a permissions issue. The technician should review the user’s effective file and folder permissions, group memberships, inherited permissions, and any explicit deny settings that could affect access. The goal is to confirm that the user has the minimum rights needed without granting unnecessary administrative permissions. Screen resolution and power settings are unrelated to file access, and a DNS suffix affects name resolution rather than authorization. Permission troubleshooting should also consider whether both share permissions and NTFS permissions apply to the resource, because the most restrictive effective access can limit the user.

Question 144.

Which Windows permission generally gives a user the ability to read, modify, create, and delete files while not necessarily allowing permission changes or ownership changes?

  1. Read
    2. Read & Execute
    3. Full Control
    4. Modify

Correct Answer: 4

Explanation:

The Modify permission generally allows a user to read, create, change, and delete files and folders without granting all of the administrative capabilities associated with Full Control. Full Control also includes the ability to change permissions and take ownership, making it more powerful than necessary for many users. Read and Read & Execute provide much more limited access. The principle of least privilege suggests that technicians should grant Modify only when users need to actively work with files. Effective permissions may come from multiple group memberships, so the technician should review combined access rather than looking only at one permission entry.

Question 145.

A user needs to work with files in a shared department folder but should not be able to alter folder permissions. Which permission is generally more appropriate than Full Control?

  1. Modify
    2. Take Ownership
    3. Change Permissions
    4. Full Control

Correct Answer: 1

Explanation:

Modify is generally more appropriate when users need to create, edit, and delete files but do not need administrative control over the folder itself. Granting Full Control would also allow the user to change permissions and potentially take ownership, which may violate least-privilege requirements. Take Ownership and Change Permissions are administrative capabilities rather than ordinary working permissions. Security is easier to manage when access is assigned through groups instead of individual accounts. Technicians should also review inherited permissions and share-level permissions when a folder is accessed across the network, since effective access can depend on both layers.

Question 146.

Which Windows feature should a technician use to encrypt an entire laptop drive so that data remains protected if the laptop is stolen?

  1. File History
    2. BitLocker
    3. Windows Defender Firewall
    4. System Restore

Correct Answer: 2

Explanation:

BitLocker provides full-volume encryption and is designed to protect data stored on a drive from unauthorized offline access. It is particularly useful for laptops because a stolen device may otherwise expose the contents of the storage drive even if the Windows password is not known. BitLocker can work with TPM hardware and may require additional startup authentication depending on policy. File History protects versions of user files, Windows Defender Firewall controls network traffic, and System Restore rolls back selected system changes. Recovery keys should be stored securely because they may be required if the normal unlocking process fails.

Question 147.

Which Windows technology provides file-level encryption on an NTFS volume instead of encrypting the entire drive?

  1. BitLocker
    2. Secure Boot
    3. Encrypting File System
    4. Windows Sandbox

Correct Answer: 3

Explanation:

Encrypting File System, or EFS, can encrypt individual files and folders stored on supported NTFS volumes. This differs from BitLocker, which encrypts an entire volume. EFS can be useful when only selected data needs file-level confidentiality, but proper certificate and key management is critical. If the required encryption certificate and private key are lost and no recovery mechanism exists, legitimate users may lose access to the data. Secure Boot protects the startup process, and Windows Sandbox provides an isolated temporary operating environment. EFS is specifically intended for selective file and folder encryption.

Question 148.

A technician is preparing to encrypt a laptop with BitLocker. Which item should be securely backed up before the deployment is considered complete?

  1. Desktop wallpaper
    2. Browser history
    3. Temporary files
    4. BitLocker recovery key

Correct Answer: 4

Explanation:

The BitLocker recovery key should be securely backed up because it may be required if the normal unlocking method fails. Situations such as TPM changes, firmware updates, hardware replacement, or certain startup security events can trigger a recovery prompt. Without the recovery key, authorized access to the encrypted data may be difficult or impossible. The key should be stored according to organizational policy in a secure location that is separate from the protected device. Browser history, temporary files, and wallpaper are not critical encryption-recovery information. Key management is a fundamental part of any encryption deployment.

Question 149.

Which Windows security feature helps prevent untrusted bootloaders from running before the operating system starts?

  1. Secure Boot
    2. File History
    3. Screen saver
    4. Disk Cleanup

Correct Answer: 1

Explanation:

Secure Boot is a UEFI feature that validates digital signatures of boot components before allowing them to execute. This helps reduce the risk of bootkits and other malicious software that attempts to compromise a system before Windows security controls become active. Secure Boot is part of a broader trusted-startup architecture and complements technologies such as TPM and BitLocker. File History protects user files, a screen saver does not validate boot software, and Disk Cleanup removes temporary or unnecessary data. Secure Boot primarily protects the integrity of the startup process.

Question 150.

A technician needs to test an unknown but potentially unsafe application without permanently changing the host Windows installation. Which feature is most appropriate?

  1. System Restore
    2. Windows Sandbox
    3. Disk Management
    4. File History

Correct Answer: 2

Explanation:

Windows Sandbox provides a temporary, isolated Windows environment where software can be executed separately from the main operating system. When the sandbox is closed, the temporary environment and changes made inside it are discarded. This makes it useful for testing unknown applications or examining software that is not yet trusted. It does not replace a dedicated malware-analysis environment for highly dangerous samples, but it provides practical isolation for many support scenarios. System Restore rolls back certain system changes, Disk Management handles storage, and File History maintains versions of user data.

Question 151.

A company wants to prevent users from installing software unless it has been approved by IT. Which combination of controls is most appropriate?

  1. Give all users administrator rights and rely on policy reminders
    2. Disable passwords to simplify support
    3. Use standard user accounts and application-control policies
    4. Share one administrator account among employees

Correct Answer: 3

Explanation:

Standard user accounts combined with application-control policies provide stronger protection against unauthorized software installation. Standard users have fewer privileges than administrators, reducing the ability of untrusted applications to make system-wide changes. Application-control technologies can further restrict which programs are allowed to run. Giving everyone administrator rights would increase malware and configuration risk. Shared administrator accounts weaken accountability, and disabling passwords is obviously insecure. Least privilege works best when combined with centralized software deployment, patch management, endpoint protection, and clear processes for requesting approved applications.

Question 152.

Which authentication method uses two different factor categories, such as a password and a fingerprint?

  1. Single sign-on
    2. Password history
    3. Account lockout
    4. Multifactor authentication

Correct Answer: 4

Explanation:

Multifactor authentication requires authentication factors from two or more different categories. A password represents something the user knows, while a fingerprint represents something the user is. Because these factors are independent, compromising one does not automatically compromise the entire authentication process. Single sign-on allows one authentication event to provide access to multiple systems but does not necessarily use multiple factors. Password history prevents recent password reuse, while account lockout limits repeated failed attempts. MFA is one of the strongest practical ways to reduce the impact of stolen or guessed passwords.

Question 153.

Which authentication factor category is represented by a hardware security token?

  1. Something you have
    2. Something you know
    3. Something you are
    4. Somewhere you are

Correct Answer: 1

Explanation:

A hardware security token represents “something you have.” Other possession factors include smart cards and certain mobile authentication devices. “Something you know” includes passwords and PINs, while “something you are” includes biometrics such as fingerprints or facial characteristics. Location can sometimes be used as contextual information but is a different category. Strong MFA implementations combine distinct factor types, such as a password and a hardware token. Technicians should not count two passwords as two separate factors because both belong to the same knowledge category.

Question 154.

Which authentication factor category is represented by a PIN?

  1. Something you are
    2. Something you know
    3. Something you have
    4. Somewhere you are

Correct Answer: 2

Explanation:

A PIN is a knowledge factor, or “something you know,” because authentication depends on information memorized by the user. Passwords and answers to security questions are other knowledge factors. Biometric characteristics such as fingerprints represent “something you are,” while physical tokens and smart cards represent “something you have.” A strong multifactor design combines different categories rather than merely using multiple credentials from the same category. Although a PIN may be shorter than a password, its security characteristics can differ depending on where and how it is used, such as when tied to a specific protected device.

Question 155.

Which security policy is intended to stop users from cycling rapidly through passwords and returning to a recently used password?

  1. Account lockout duration
    2. Screen lock timeout
    3. Password history
    4. File retention

Correct Answer: 3

Explanation:

Password history prevents users from immediately reusing one of a specified number of previous passwords. This is useful when an organization enforces password changes and wants to discourage users from simply cycling through a few familiar passwords. Account lockout controls repeated failed authentication attempts, screen lock timeout protects unattended sessions, and file retention determines how long data is kept. Password history is most effective when combined with appropriate password length, MFA, secure reset procedures, and monitoring rather than being relied upon as the only password-security mechanism.

Question 156.

Which security control automatically locks or disables an account after a configured number of failed login attempts?

  1. Password history
    2. File permissions
    3. BitLocker
    4. Account lockout policy

Correct Answer: 4

Explanation:

An account lockout policy limits repeated password-guessing attempts by temporarily locking an account after a specified number of failed authentication attempts. This can slow brute-force attacks, although organizations must configure the threshold carefully to avoid making denial-of-service attacks too easy. Password history prevents password reuse, file permissions control resource access, and BitLocker encrypts storage. Account lockout should be combined with MFA, secure password practices, monitoring, and alerts for suspicious authentication patterns. Technicians should also understand how users regain access when lockouts occur.

Question 157.

A user receives an email containing an urgent message that appears to come from the company’s finance department and asks the user to enter credentials on a linked website. Which attack is being attempted?

  1. Phishing
    2. Tailgating
    3. Shoulder surfing
    4. Dumpster diving

Correct Answer: 1

Explanation:

Phishing uses deceptive electronic messages to trick recipients into revealing credentials, opening malicious attachments, or visiting fraudulent websites. Attackers often create urgency, impersonate trusted departments, or use realistic branding to increase credibility. Tailgating is a physical access technique, shoulder surfing involves observing sensitive information, and dumpster diving involves searching discarded materials. Users should verify unexpected requests through trusted channels, avoid clicking suspicious links, and report phishing attempts. Email security controls can help, but user awareness remains important because sophisticated phishing messages may bypass technical filtering.

Question 158.

Which social-engineering attack specifically targets executives or other high-value individuals with carefully crafted fraudulent messages?

  1. Smishing
    2. Whaling
    3. Tailgating
    4. Shoulder surfing

Correct Answer: 2

Explanation:

Whaling is a targeted form of phishing aimed at executives, senior managers, or other high-value individuals who may have access to sensitive information or authority over financial transactions. Attackers often research their targets and create convincing messages involving legal requests, invoices, confidential documents, or urgent executive decisions. Smishing uses text messages, tailgating is a physical access technique, and shoulder surfing involves observing information visually. Organizations should require independent verification for high-risk financial and administrative requests because whaling attacks often rely on urgency and authority to bypass normal procedures.

Question 159.

A user receives a text message claiming a package cannot be delivered until the user signs in through a provided link. Which type of attack is this?

  1. Vishing
    2. Whaling
    3. Smishing
    4. Tailgating

Correct Answer: 3

Explanation:

Smishing is phishing conducted through SMS or similar text messaging services. Attackers frequently impersonate delivery companies, financial institutions, government agencies, or employers and try to create urgency so the victim clicks a malicious link. The linked page may attempt to steal credentials, payment information, or install malware. Vishing uses voice communication, whaling targets high-value individuals, and tailgating is a physical security attack. Users should avoid clicking unexpected text-message links and instead verify notifications through official applications or independently accessed websites.

Question 160.

A technician successfully resolves a malware incident, verifies the workstation is functioning properly, and confirms that updates and endpoint protection are current. What is the final troubleshooting step?

  1. Disable automatic updates
    2. Remove the user’s password
    3. Clear all event logs
    4. Document findings, actions, results, and preventive recommendations

Correct Answer: 4

Explanation:

Documentation is the final step after the technician has verified full system functionality and confirmed that the original problem is resolved. The support record should describe the reported symptoms, troubleshooting process, identified cause, remediation steps, updates or configuration changes, verification results, and any recommendations intended to reduce recurrence. For a malware incident, documentation can also support security trend analysis and future incident response. Disabling updates or removing authentication would weaken security, while clearing logs could destroy useful diagnostic or investigative information. Good documentation improves accountability, knowledge sharing, and the efficiency of future troubleshooting.