CompTIA A+ 220-1102 Practice Test Questions and Exam Dumps Part10 Q181-200

View Full CompTIA A+ 220-1102 Exam Dumps and Practice Test Dumps

 

Question 181.

A Windows computer is running out of storage because temporary files, cached update files, and other unnecessary system data have accumulated. Which built-in utility should the technician use first?

  1. Disk Cleanup
    2. Device Manager
    3. Local Security Policy
    4. Event Viewer

Correct Answer: 1

Explanation:

Disk Cleanup is a Windows utility designed to identify and remove unnecessary files that can consume storage space. Depending on the Windows version and available options, it can help remove temporary files, thumbnails, cached installation files, old update-related files, and other system-generated data. This makes it a logical first step when a workstation is low on disk capacity because of accumulated temporary content. Device Manager is used for hardware and driver management, Local Security Policy controls local security settings, and Event Viewer stores diagnostic logs. Before deleting large amounts of data, the technician should review what is selected and confirm that user-created files are not being removed. If storage remains critically low afterward, the technician should investigate large applications, user files, restore points, or storage upgrades.

Question 182.

Which Windows utility should a technician use to create a new partition on an unallocated portion of a disk?

  1. Task Scheduler
    2. Disk Management
    3. Windows Firewall
    4. Reliability Monitor

Correct Answer: 2

Explanation:

Disk Management is the standard graphical Windows utility for managing disks, partitions, and volumes. A technician can use it to initialize disks, create new volumes from unallocated space, assign drive letters, format supported file systems, and in appropriate situations extend or shrink existing volumes. Task Scheduler is used to automate programs or scripts, Windows Firewall controls network traffic, and Reliability Monitor provides a history of stability events. Storage changes should always be performed carefully because deleting, formatting, or modifying the wrong partition can cause data loss. Before making significant changes, the technician should confirm the correct disk, verify backups, and understand the existing partition layout. Disk Management is appropriate for common volume-administration tasks without requiring the more advanced command-line capabilities of tools such as DiskPart.

Question 183.

A technician needs a command-line utility for advanced disk and partition management in Windows. Which command should be used?

  1. netstat
    2. gpresult
    3. diskpart
    4. nslookup

Correct Answer: 3

Explanation:

DiskPart is a Windows command-line utility used to manage disks, partitions, volumes, and certain storage attributes. It can perform actions such as listing disks, selecting disks, creating partitions, cleaning disks, assigning drive letters, and formatting volumes. Because DiskPart can make destructive changes very quickly, the technician should verify the selected disk and command before executing modifications. netstat displays network connections and listening ports, gpresult reports Group Policy information, and nslookup queries DNS. DiskPart is generally chosen when graphical Disk Management is insufficient or when storage operations need to be scripted. The technician should maintain current backups and use particular caution with commands such as clean, which can remove partition information from the selected disk.

Question 184.

Which Windows file system is generally the best choice for an internal system drive that requires permissions, journaling, compression, and support for large files?

  1. FAT32
    2. exFAT
    3. FAT16
    4. NTFS

Correct Answer: 4

Explanation:

NTFS is the standard file system used for modern Windows system drives because it supports advanced capabilities such as access-control permissions, journaling, compression, encryption through EFS, disk quotas, and very large files and volumes. FAT32 provides broad compatibility but lacks many of these security and reliability features and has a relatively small individual file-size limit. exFAT is useful for removable media that needs large-file support and cross-platform compatibility, but it does not provide the same Windows permission and journaling features as NTFS. FAT16 is an older file system with significant limitations. For an internal Windows system volume that requires security, resilience, and modern storage capabilities, NTFS is generally the most appropriate choice.

Question 185.

A technician needs a removable drive that will regularly be used between Windows and other modern operating systems and must store files larger than 4 GB. Which file system is most appropriate?

  1. exFAT
    2. FAT16
    3. NTFS only
    4. ISO 9660

Correct Answer: 1

Explanation:

exFAT is commonly used on removable storage when large-file support and broad compatibility across modern operating systems are important. FAT32 is widely supported but has a maximum individual file size of approximately 4 GB, which can be a major limitation for large videos, disk images, or backup files. NTFS supports large files and advanced Windows security features, but it may not provide the same read/write compatibility across every non-Windows platform. ISO 9660 is associated primarily with optical-disc file systems. The correct file system depends on the use case, but exFAT is often the best compromise for portable storage that needs to handle large files and move between different modern systems without requiring Windows-specific permissions.

Question 186.

A Windows user cannot open a file because the file extension is hidden and the technician suspects the file is not the type it appears to be. Which setting should be changed?

  1. Windows Firewall profile
    2. File Explorer option to show file name extensions
    3. BitLocker startup mode
    4. Power plan

Correct Answer: 2

Explanation:

Windows can hide extensions for known file types, which can make a file appear more trustworthy than it really is. For example, a malicious executable could use a misleading name and icon if the .exe extension is hidden. Enabling the option to show file name extensions in File Explorer helps users and technicians identify the actual file type. This is useful for both troubleshooting and security awareness. Windows Firewall profiles control network traffic, BitLocker protects encrypted volumes, and power plans control energy and performance settings. Showing file extensions does not by itself guarantee that a file is safe, so suspicious files should still be scanned with security software and handled according to organizational policy.

Question 187.

Which Windows utility should a technician use to review whether a hardware device has been disabled or is reporting a driver problem?

  1. Task Scheduler
    2. File History
    3. Device Manager
    4. Disk Cleanup

Correct Answer: 3

Explanation:

Device Manager provides a centralized view of hardware devices recognized by Windows and shows whether devices are functioning normally, disabled, or experiencing driver or resource problems. Warning icons and device status codes can provide useful troubleshooting clues. A technician can use Device Manager to update, roll back, uninstall, disable, or re-enable drivers and devices when appropriate. Task Scheduler automates tasks, File History protects versions of user files, and Disk Cleanup removes unnecessary data. When a peripheral stops functioning after a driver update or hardware change, Device Manager is usually one of the first Windows utilities a technician should examine. Any driver changes should be followed by testing to confirm stable operation.

Question 188.

A newly installed driver causes a network adapter to stop working properly. Which action is the least disruptive first step if the previous driver was working?

  1. Reinstall Windows
    2. Replace the motherboard
    3. Format the disk
    4. Roll back the driver

Correct Answer: 4

Explanation:

Rolling back the driver is a logical first step when a device begins malfunctioning immediately after a driver update and the previous version worked correctly. Device Manager may provide a Roll Back Driver option if Windows still has the prior version available. This follows a basic troubleshooting principle: reverse the most recent relevant change before performing more disruptive actions. Reinstalling Windows, formatting the disk, or replacing the motherboard would introduce unnecessary risk and downtime without evidence that those actions are required. After rolling back the driver, the technician should verify that the adapter functions normally and then investigate whether a newer corrected driver is available from a trusted source.

Question 189.

Which Windows command should a technician run to check protected operating-system files for corruption and attempt to replace damaged copies?

  1. sfc /scannow
    2. net use
    3. route print
    4. tasklist

Correct Answer: 1

Explanation:

The sfc /scannow command runs Windows System File Checker, which examines protected operating-system files and attempts to replace corrupted or incorrect copies with valid versions. It is useful when Windows components behave unpredictably, applications relying on system files fail, or operating-system corruption is suspected. net use manages network-share connections, route print displays the routing table, and tasklist lists running processes. If SFC cannot repair corrupted files because the Windows component store itself is damaged, a technician may need to use DISM to repair the Windows image and then run SFC again. System-file repair is generally less disruptive than reinstalling the operating system.

Question 190.

Which Windows tool is commonly used to repair the component store when System File Checker reports that it cannot repair some corrupted files?

  1. tracert
    2. DISM
    3. hostname
    4. arp

Correct Answer: 2

Explanation:

DISM, or Deployment Image Servicing and Management, can repair the Windows image and component store used by System File Checker. In a common troubleshooting workflow, the technician runs a supported DISM repair command when SFC cannot repair damaged protected files and then runs sfc /scannow again. tracert traces network hops, hostname shows the local computer name, and arp works with local IP-to-MAC mappings. DISM is a powerful Windows servicing utility, so technicians should use the correct parameters for the situation. It can also perform other image-management functions beyond repair, but in CompTIA-style troubleshooting it is particularly relevant when deeper Windows image corruption is suspected.

Question 191.

A computer repeatedly crashes after a software change, and the user wants to return system settings to a previous state without intentionally restoring personal documents. Which feature is most appropriate?

  1. File History
    2. BitLocker
    3. System Restore
    4. Storage Spaces

Correct Answer: 3

Explanation:

System Restore uses restore points to return selected Windows system files, registry settings, drivers, and configuration information to an earlier state. It is useful when a newly installed application, driver, or configuration change causes instability. System Restore is not intended to be a complete user-data backup and generally focuses on system configuration rather than personal documents. File History is designed for recovering versions of user files, BitLocker encrypts storage, and Storage Spaces provides pooling and resiliency. Before performing a restore, the technician should consider recent changes and confirm that a suitable restore point exists. Afterward, the system should be tested to ensure both the original problem and any side effects have been resolved.

Question 192.

Which Windows recovery tool is designed to automatically diagnose and repair certain problems that prevent Windows from booting?

  1. Disk Cleanup
    2. File History
    3. Task Manager
    4. Startup Repair

Correct Answer: 4

Explanation:

Startup Repair is available through Windows Recovery Environment and is designed to diagnose and correct certain startup-related problems automatically. It can address issues involving boot configuration, startup files, and some forms of system corruption that prevent Windows from loading normally. Disk Cleanup removes temporary files, File History protects user data, and Task Manager requires a functioning Windows environment for normal use. Startup Repair is an appropriate early recovery option because it attempts targeted repairs without immediately reinstalling the operating system. If it fails, the technician can move to other WinRE tools such as System Restore, command-line repair utilities, or more advanced recovery options.

Question 193.

A technician must install software that requires administrative rights, but the user normally works with a standard account. Which Windows security mechanism prompts for elevation when necessary?

  1. User Account Control
    2. File History
    3. Disk Management
    4. Secure Boot

Correct Answer: 1

Explanation:

User Account Control, or UAC, helps limit unnecessary administrative privilege by prompting for consent or administrative credentials when an operation requires elevated rights. This allows users to perform ordinary tasks with a standard or filtered security context while elevating only when necessary. File History protects user files, Disk Management manages storage, and Secure Boot helps protect the startup process. UAC is not a replacement for least privilege, but it supports that principle by separating everyday use from administrative actions. Organizations should avoid simply disabling UAC because repeated prompts are inconvenient; instead, applications and workflows should be designed so elevation is required only for legitimate administrative tasks.

Question 194.

Which type of user account should employees normally use for routine daily activities when administrative privileges are not required?

  1. Shared administrator account
    2. Standard user account
    3. Guest account with no password
    4. Built-in Administrator account

Correct Answer: 2

Explanation:

A standard user account is generally the most appropriate account type for routine work because it limits the ability to make system-wide changes. This supports least privilege and reduces the potential damage caused by user error, malicious software, or stolen credentials. Administrative rights can be provided through controlled elevation when a legitimate task requires them. Shared administrator accounts reduce accountability, a guest account is too limited and inappropriate for normal employee identity, and using the built-in Administrator account for everyday work creates unnecessary risk. Separating routine and privileged activity is a foundational security practice and is especially important on systems that handle sensitive organizational information.

Question 195.

Which security control is most directly intended to prevent unauthorized people from learning confidential information by looking at a user’s monitor from the side?

  1. Cable lock
    2. Door alarm
    3. Privacy filter
    4. UPS

Correct Answer: 3

Explanation:

A privacy filter limits the viewing angle of a monitor so that information becomes difficult to read from the side. This reduces the risk of shoulder surfing in public or shared environments such as airports, trains, offices, classrooms, or coffee shops. A cable lock protects a device from theft, a door alarm detects certain physical access events, and a UPS provides backup electrical power. Privacy filters should be combined with other good practices, such as locking the screen when stepping away, positioning the display carefully, and avoiding sensitive work in uncontrolled environments. Physical confidentiality controls remain important even when strong digital security mechanisms are already in place.

Question 196.

Which type of social-engineering attack occurs when a criminal impersonates support staff over the phone and asks for a user’s password or MFA code?

  1. Tailgating
    2. Shoulder surfing
    3. Smishing
    4. Vishing

Correct Answer: 4

Explanation:

Vishing is voice-based phishing in which an attacker uses telephone or voice communication to manipulate a victim into revealing sensitive information or performing an unsafe action. The attacker may claim to be technical support, a financial institution, law enforcement, or another trusted party. Employees should never provide passwords or MFA codes to unsolicited callers and should verify requests using trusted contact channels. Smishing uses text messages, tailgating is a physical-access technique, and shoulder surfing involves visually observing sensitive information. Security awareness training is important because technical controls cannot fully prevent a user from voluntarily disclosing authentication information to a convincing attacker.

Question 197.

A user receives a fraudulent SMS message with a link that requests corporate credentials. Which attack is being used?

  1. Smishing
    2. Whaling
    3. Tailgating
    4. Dumpster diving

Correct Answer: 1

Explanation:

Smishing is phishing delivered through SMS or similar text messaging platforms. Attackers may impersonate banks, employers, delivery companies, or government agencies and create urgency to persuade users to click malicious links. Those links may lead to credential-harvesting pages, malware, or financial fraud. Whaling is targeted phishing directed at high-value individuals such as executives, tailgating involves following an authorized person into a restricted area, and dumpster diving involves searching discarded material for useful information. Users should avoid clicking unexpected links and independently access legitimate services through known applications or websites. Suspicious messages should also be reported so the organization can warn others and investigate related activity.

Question 198.

Which type of malware is specifically designed to hide its presence and maintain privileged or persistent access to a compromised system?

  1. Adware
    2. Rootkit
    3. Spam
    4. Cookie

Correct Answer: 2

Explanation:

A rootkit is malicious software designed to conceal its own presence or the presence of other malicious components while maintaining persistent or privileged access. Rootkits can operate at different layers of the system and may interfere with normal security tools, making detection and removal difficult. Adware mainly displays unwanted advertisements, spam refers to unsolicited messages, and cookies are commonly legitimate browser data structures. Because rootkits can undermine system trust, remediation may sometimes require offline scanning, trusted recovery media, or complete reimaging rather than relying only on removal within the compromised operating system. The exact response should follow organizational incident-response procedures and the sensitivity of the affected system.

Question 199.

Which malware type can spread automatically from one vulnerable computer to another without requiring a user to manually launch it on each system?

  1. Trojan
    2. Adware
    3. Worm
    4. Logic bomb

Correct Answer: 3

Explanation:

A worm is self-propagating malware that can spread automatically across systems or networks, often by exploiting vulnerabilities, weak services, or poor network security. This ability can allow a worm to infect many computers rapidly without requiring users to manually execute the malware on every device. Trojans typically depend on users being tricked into running them, adware focuses on unwanted advertising, and logic bombs activate when a specific condition occurs. Defenses against worms include prompt patching, network segmentation, host firewalls, endpoint protection, disabling unnecessary services, and monitoring. If a worm is detected, rapid isolation of affected systems can be essential to stop further propagation across the organization.

Question 200.

A technician has implemented a fix for a recurring Windows problem, confirmed that the original issue is resolved, and checked that all related functions operate correctly. What should be done next according to standard troubleshooting methodology?

  1. Make unrelated configuration changes
    2. Remove the user’s security controls
    3. Delete the diagnostic history
    4. Document findings, actions, and outcomes

Correct Answer: 4

Explanation:

After a solution has been implemented and full system functionality has been verified, the technician should document the findings, actions, and outcomes. Good documentation should record the original symptoms, troubleshooting steps, root cause when known, corrective action, any relevant configuration changes, test results, and preventive recommendations. This creates a reliable support history, improves knowledge sharing, and helps future technicians recognize recurring problems more quickly. Making unrelated changes after the issue is solved can introduce new problems, while deleting diagnostic information reduces accountability and troubleshooting value. Documentation is therefore the final step in the standard CompTIA troubleshooting methodology and helps ensure the incident is closed professionally and consistently.