View Full CompTIA A+ 220-1102 Exam Dumps and Practice Test Dumps
Question 201.
A Windows technician wants to prevent a specific application from automatically launching every time a user signs in. Which built-in utility is most appropriate?
- Task Manager
2. Disk Management
3. Event Viewer
4. Device Manager
Correct Answer: 1
Explanation:
Task Manager includes a Startup section that allows technicians to review applications configured to launch automatically when a user signs in. From this interface, unnecessary startup applications can be disabled without uninstalling the software. This can improve startup performance and reduce unnecessary CPU or memory consumption. Disk Management is used for disks, partitions, and volumes, while Event Viewer provides system and application logs. Device Manager is designed for hardware devices and drivers. When troubleshooting a computer that takes a long time to become usable after sign-in, reviewing startup applications is a useful first step. The technician should avoid disabling security software, required management agents, or business-critical applications without first understanding their role.
Question 202.
Which Windows utility should a technician use to determine which processes are consuming the most memory on a workstation?
- System Restore
2. Task Manager
3. BitLocker
4. Disk Cleanup
Correct Answer: 2
Explanation:
Task Manager displays real-time resource usage for running applications and processes, including memory, CPU, disk, network, and GPU utilization. A technician can sort the Processes tab by memory usage to identify applications that are consuming unusually large amounts of RAM. This is useful when troubleshooting slow performance, paging, or application instability. System Restore rolls back selected system configuration changes, BitLocker encrypts storage volumes, and Disk Cleanup removes unnecessary files. Identifying the resource-intensive process is only part of troubleshooting; the technician should then determine whether the behavior is expected, caused by a memory leak, related to malware, or due to insufficient system memory. Changes should be made only after the cause is reasonably understood.
Question 203.
A technician needs to review application crashes that occurred over the last several days and correlate them with recently installed updates. Which Windows tool is most useful?
- Device Manager
2. Task Scheduler
3. Reliability Monitor
4. File History
Correct Answer: 3
Explanation:
Reliability Monitor provides a timeline of system stability events, including application failures, Windows failures, hardware errors, updates, and software installations. This makes it particularly useful when a problem began recently and the technician wants to determine whether the timing corresponds with a system change. Device Manager focuses on hardware and driver status, Task Scheduler is used to automate tasks, and File History maintains versions of user files. Reliability Monitor does not replace Event Viewer, but it provides an easier high-level view of system stability over time. After identifying a suspicious update or application installation, the technician can gather more detailed information from Event Viewer or other diagnostic tools before deciding whether to roll back or remove the change.
Question 204.
Which Windows utility stores detailed logs for application errors, security events, service failures, and operating-system problems?
- Disk Management
2. Task Manager
3. File Explorer
4. Event Viewer
Correct Answer: 4
Explanation:
Event Viewer provides access to Windows logs such as Application, Security, System, and other specialized event channels. These logs are useful for diagnosing service failures, application crashes, authentication problems, driver issues, and many other conditions. A technician can filter events by severity, source, date, or event ID to narrow an investigation. Disk Management handles disks and volumes, Task Manager provides real-time process and performance information, and File Explorer is primarily used for file management. Event Viewer is especially valuable for intermittent problems because it maintains a history that can be reviewed after the failure is no longer occurring. Technicians should avoid clearing logs during troubleshooting because doing so can remove valuable evidence needed to identify the root cause.
Question 205.
A Windows service should start automatically each time the computer boots. Which utility should a technician use to configure this behavior?
- Services
2. File History
3. Device Manager
4. Disk Cleanup
Correct Answer: 1
Explanation:
The Services management console allows technicians to view Windows services, start or stop them, and configure startup types such as Automatic, Manual, and Disabled. If a required service is not starting after reboot, the technician can review its startup configuration and dependencies. File History protects versions of user files, Device Manager manages hardware and drivers, and Disk Cleanup removes temporary and unnecessary files. Changing a service to Automatic should be done only when the service is actually required because unnecessary services can consume resources or expand the attack surface. If the service fails even when configured correctly, the technician should review its dependencies and relevant Event Viewer logs to determine why startup is unsuccessful.
Question 206.
Which Windows command should a technician use to display detailed TCP/IP information, including the default gateway, DNS servers, DHCP server, and physical address?
- ping
2. ipconfig /all
3. tasklist
4. tracert
Correct Answer: 2
Explanation:
The ipconfig /all command displays detailed network adapter configuration on a Windows computer. Information can include the IPv4 and IPv6 addresses, subnet mask, default gateway, DNS servers, DHCP status, DHCP server, lease details, and the adapter’s physical or MAC address. This makes the command useful for diagnosing incorrect addressing, DNS configuration, DHCP problems, and adapter identification. ping tests basic reachability, tasklist displays running processes, and tracert shows the path toward a network destination. A technician investigating network connectivity should compare the displayed settings with the expected configuration and then determine whether the issue lies with DHCP, DNS, routing, the adapter, or another network component.
Question 207.
A Windows computer has an incorrect DHCP address. Which command should the technician use first to give up the current DHCP lease?
- ipconfig /flushdns
2. nslookup
3. ipconfig /release
4. netstat
Correct Answer: 3
Explanation:
The ipconfig /release command releases the current DHCP-assigned address on applicable Windows network adapters. It is commonly followed by ipconfig /renew, which requests a new lease from the DHCP server. This sequence can help when a workstation has stale or incorrect dynamically assigned configuration. ipconfig /flushdns clears cached DNS records, nslookup queries DNS, and netstat displays network connections and listening ports. If the computer receives another incorrect address after renewal, the technician should investigate deeper causes such as DHCP scope configuration, VLAN assignment, an unauthorized DHCP server, or physical network connectivity. Releasing the lease alone does not correct a misconfigured DHCP infrastructure.
Question 208.
Which command should be used after releasing a DHCP lease to request a new configuration from the DHCP server?
- tracert
2. arp -a
3. route print
4. ipconfig /renew
Correct Answer: 4
Explanation:
The ipconfig /renew command requests a new DHCP lease for applicable Windows network adapters. It is typically used after ipconfig /release when troubleshooting dynamic addressing problems. A successful renewal may provide a new IP address, subnet mask, gateway, DNS configuration, and other DHCP options. tracert displays network hops, arp -a shows local IPv4-to-MAC mappings, and route print displays the local routing table. If renewal fails, the technician should check whether the adapter is enabled, whether the computer has link connectivity, whether the DHCP server is available, and whether the system is located on the correct VLAN or subnet. Automatic private addresses can be a sign that DHCP communication is failing.
Question 209.
A technician can successfully ping a server by IP address, but the server name cannot be resolved. Which command is most appropriate for troubleshooting the problem?
- nslookup
2. sfc /scannow
3. chkdsk
4. taskkill
Correct Answer: 1
Explanation:
nslookup queries DNS and helps determine whether a hostname can be resolved to the expected IP address. If a server can be reached by its IP address but not by name, basic IP connectivity is working and DNS is a likely area to investigate. The technician can use nslookup to see which DNS server is being queried and whether the expected record is returned. sfc /scannow checks Windows system files, chkdsk checks disk and file-system integrity, and taskkill terminates processes. Additional steps may include checking ipconfig /all, clearing the local DNS cache, verifying the DNS record, and confirming that the workstation is configured to use the correct DNS server.
Question 210.
Which Windows command clears cached DNS information on the local workstation?
- net use
2. ipconfig /flushdns
3. tasklist
4. gpresult
Correct Answer: 2
Explanation:
The ipconfig /flushdns command clears the Windows DNS resolver cache. This is useful when a workstation has stored an old or incorrect DNS record after a server’s IP address has changed or after a DNS record was corrected. Once the cache is cleared, Windows must perform a fresh DNS query the next time that hostname is requested. net use manages network share connections, tasklist displays processes, and gpresult reports applied Group Policy. Flushing DNS does not change the configured DNS servers and will not repair an incorrect DNS record on the DNS server itself. The technician should therefore verify both local configuration and authoritative DNS data when name-resolution problems persist.
Question 211.
A technician needs to identify the intermediate routers between a workstation and a remote server. Which command should be used?
- taskkill
2. hostname
3. tracert
4. gpupdate
Correct Answer: 3
Explanation:
The tracert command displays the route packets take toward a network destination by showing intermediate hops. It can help identify where connectivity stops or where significant latency appears. This is useful when local network communication works but access to a remote site or service fails. Some routers may not respond to traceroute probes because of firewall or security policies, so a timeout at one hop does not automatically indicate a failure. taskkill terminates processes, hostname displays the local computer’s name, and gpupdate refreshes Group Policy. Tracert should be used together with tools such as ping, DNS tests, and routing information to build a complete picture of a connectivity problem.
Question 212.
Which Windows command displays active connections and listening network ports?
- chkdsk
2. sfc
3. net use
4. netstat
Correct Answer: 4
Explanation:
netstat displays network-related information such as active connections, listening TCP or UDP ports, protocol statistics, and, with appropriate switches, process identifiers. This makes it useful when determining whether an application is listening on the expected port or when investigating unusual outbound connections. chkdsk checks disks and file systems, sfc verifies protected Windows system files, and net use manages mapped network resources. Netstat can help narrow the difference between an application problem and a network problem. For example, if a server application is not listening on the expected port, troubleshooting should focus on the service or application rather than immediately changing firewall or routing settings.
Question 213.
Which Windows command displays IP-to-MAC address mappings stored in the local ARP cache?
- arp -a
2. nslookup
3. tasklist
4. gpresult
Correct Answer: 1
Explanation:
The arp -a command displays the local Address Resolution Protocol cache. The cache contains mappings between IPv4 addresses and MAC addresses learned for devices on the local network segment. This can help diagnose local communication problems or identify unexpected hardware address mappings. nslookup queries DNS, tasklist displays running processes, and gpresult reports Group Policy information. ARP is relevant only to communication on the local Layer 2 segment; packets destined for remote networks are normally sent to the MAC address of the default gateway instead. If suspicious or incorrect ARP entries are observed, the technician should investigate possible duplicate addressing, stale information, or security issues rather than simply assuming the network adapter is faulty.
Question 214.
A technician needs to view the IPv4 routing table on a Windows workstation. Which command is most appropriate?
- hostname
2. route print
3. format
4. taskkill
Correct Answer: 2
Explanation:
The route print command displays the local routing table, including destination networks, masks, gateways, interfaces, and routing metrics. It is particularly useful when a system has multiple adapters, VPN connections, or manually configured routes and traffic appears to be taking an unexpected path. hostname displays the computer’s name, format prepares a storage volume, and taskkill terminates processes. Routing problems may cause communication to fail even when the system has a valid IP address and working DNS. Reviewing the routing table can help identify an incorrect default route, overly specific static route, or unexpected VPN route that is redirecting traffic.
Question 215.
A user receives an unexpected email directing the user to a fake Microsoft 365 login page. Which type of attack is being attempted?
- Tailgating
2. Vishing
3. Phishing
4. Shoulder surfing
Correct Answer: 3
Explanation:
Phishing uses deceptive messages, commonly email, to trick users into visiting fraudulent websites, opening malicious attachments, or revealing credentials. A fake Microsoft 365 sign-in page is a common credential-harvesting technique because users may recognize the familiar branding and enter their username, password, or MFA information. Tailgating is a physical access attack, vishing uses voice calls, and shoulder surfing involves observing sensitive information. Users should verify suspicious messages through trusted channels and should avoid signing in through unexpected email links. Organizations can reduce risk through email filtering, MFA, user training, conditional access, and monitoring for unusual authentication attempts, but no single control completely eliminates phishing.
Question 216.
Which social-engineering attack uses fraudulent SMS or text messages to trick users into visiting malicious sites or revealing credentials?
- Whaling
2. Tailgating
3. Vishing
4. Smishing
Correct Answer: 4
Explanation:
Smishing is phishing performed through SMS or similar text messaging platforms. Attackers often impersonate delivery services, banks, employers, government agencies, or security teams and create urgency to persuade users to click a link. The link may lead to credential theft, malware, or fraudulent payment requests. Whaling is targeted phishing aimed at high-value individuals, vishing uses telephone or voice communication, and tailgating is a physical access technique. Users should avoid tapping unexpected links and instead open the official application or website independently. Organizations should also encourage employees to report suspicious messages so security teams can warn other users and block known malicious destinations.
Question 217.
Which type of attack involves an unauthorized person following an employee through a secured door without presenting valid credentials?
- Tailgating
2. Smishing
3. Whaling
4. Vishing
Correct Answer: 1
Explanation:
Tailgating occurs when an unauthorized person enters a restricted physical area by following an authorized person through an access-controlled entrance. Attackers may rely on social pressure or politeness, such as asking someone to hold a door while carrying boxes. Technical network controls do not stop this type of attack because it targets physical access procedures and human behavior. Smishing uses text messages, whaling targets high-value individuals with phishing, and vishing uses voice communication. Countermeasures include security awareness, badge-controlled entrances, guards, cameras, mantraps where appropriate, and policies requiring each individual to authenticate rather than allowing unknown people to follow through secured doors.
Question 218.
Which security control best reduces the risk that someone standing nearby can read confidential information displayed on a laptop?
- Cable lock
2. Privacy filter
3. UPS
4. Surge protector
Correct Answer: 2
Explanation:
A privacy filter narrows the viewing angle of a screen so that information becomes difficult to read from the side. This helps reduce shoulder-surfing risk in public spaces, shared offices, airports, trains, or other locations where unauthorized people may be nearby. A cable lock helps prevent physical theft, while a UPS and surge protector address electrical power issues rather than confidentiality. Privacy filters work best when users also lock the screen when stepping away, avoid displaying sensitive information unnecessarily, and position the laptop carefully. Physical confidentiality controls are important because even strong encryption and authentication cannot prevent a nearby person from viewing information that is already displayed to an authorized user.
Question 219.
A company is disposing of an old hard drive that contained highly sensitive customer records and will not be reused. Which action provides the strongest protection against later data recovery?
- Rename the files
2. Empty the Recycle Bin
3. Physically destroy the drive according to approved policy
4. Change the drive letter
Correct Answer: 3
Explanation:
When a storage device containing highly sensitive information will not be reused, physical destruction according to an approved organizational process can provide very strong protection against later data recovery. Methods may include shredding, crushing, pulverizing, or other media-appropriate destruction techniques. Renaming files, emptying the Recycle Bin, or changing a drive letter does not remove the underlying data securely. In other scenarios, approved secure erasure, cryptographic erase, or other sanitization methods may be appropriate, especially when the drive will be reused. Technicians must follow company policy, legal requirements, and chain-of-custody procedures because improper disposal of storage media can expose confidential data long after the original computer has been retired.
Question 220.
A technician has implemented a solution, tested the system, and confirmed with the user that the original problem is resolved. According to standard troubleshooting methodology, what should the technician do next?
- Change additional unrelated settings
2. Remove existing diagnostic logs
3. Reproduce the issue intentionally
4. Document findings, actions, and outcomes
Correct Answer: 4
Explanation:
Documentation is the final step in the standard troubleshooting methodology after the technician has implemented the solution and verified full functionality. The support record should capture the symptoms, diagnostic steps, identified cause when known, corrective action, testing performed, final outcome, and any preventive recommendations. Good documentation creates useful organizational knowledge and helps future technicians resolve similar problems more efficiently. It can also support auditing, trend analysis, and accountability. Making unrelated changes after successful repair risks creating new problems, while deleting diagnostic information removes useful history. Intentionally recreating the failure is unnecessary once the fix has been tested appropriately. A complete, accurate support record allows the issue to be closed professionally and provides a reliable reference if the problem later returns.