CompTIA A+ 220-1102 Practice Test Questions and Exam Dumps Part13 Q241-260

View Full CompTIA A+ 220-1102 Exam Dumps and Practice Test Dumps

 

Question 241.

A technician needs to determine whether a Windows system is experiencing excessive paging because physical memory is nearly exhausted. Which built-in tool should be checked first?

  1. Task Manager
    2. Disk Management
    3. File History
    4. BitLocker

Correct Answer: 1

Explanation:

Task Manager provides real-time information about memory utilization and can help determine whether a system is under memory pressure. The Performance tab shows total memory, memory in use, available memory, committed memory, and related statistics, while the Processes tab helps identify applications consuming unusually large amounts of RAM. If the system is consistently using nearly all physical memory, Windows may rely more heavily on virtual memory and paging, which can reduce performance. Disk Management is used for partitions and volumes, File History protects user files, and BitLocker provides drive encryption. After identifying high memory usage, the technician should determine whether a specific application is leaking memory, too many applications are running, or the system simply needs additional RAM.

Question 242.

Which Windows feature uses a portion of storage as virtual memory when physical RAM is insufficient?

  1. Secure Boot
    2. Page file
    3. File History
    4. BitLocker

Correct Answer: 2

Explanation:

The page file is used by Windows as part of virtual memory. When available physical RAM is insufficient, Windows can move less actively used memory pages to storage so RAM can be used for more immediate workloads. Because storage is much slower than physical memory, excessive paging can noticeably reduce system performance. Secure Boot protects the startup process, File History stores versions of user data, and BitLocker encrypts volumes. The page file should normally be managed according to Windows recommendations unless there is a specific reason to change it. If a computer frequently relies heavily on paging, the underlying cause may be insufficient RAM, an application memory leak, or too many concurrent applications rather than an incorrectly sized page file.

Question 243.

A Windows computer is slow only when several large applications are running simultaneously. Task Manager shows memory usage near 100%. What is the most appropriate long-term solution?

  1. Disable Windows Firewall
    2. Reduce screen resolution
    3. Add more RAM if the system supports it
    4. Clear the ARP cache

Correct Answer: 3

Explanation:

If the system consistently reaches nearly 100% physical memory utilization when the user’s normal applications are running, adding RAM is a reasonable long-term solution if the platform supports an upgrade. More physical memory can reduce reliance on the slower page file and improve responsiveness when multitasking. Disabling Windows Firewall would create a security risk and would not solve memory pressure. Lowering the screen resolution does not meaningfully address application RAM consumption, and clearing the ARP cache is a network troubleshooting action. Before upgrading, the technician should still verify that the memory usage is legitimate and not caused by malware or an application memory leak. Hardware upgrades should be compatible with the motherboard and operating system.

Question 244.

Which Windows utility can help a technician identify which applications are consuming the most disk activity in real time?

  1. Device Manager
    2. Local Security Policy
    3. File Explorer Options
    4. Task Manager

Correct Answer: 4

Explanation:

Task Manager displays real-time disk activity by process and provides overall disk utilization information on the Performance tab. This can help determine whether a particular application, update process, antivirus scan, or other workload is saturating the storage device. Device Manager manages hardware and drivers, Local Security Policy controls security settings, and File Explorer Options changes how files and folders are displayed. High disk utilization can be caused by legitimate background activity, insufficient memory leading to paging, failing storage, malware, or poorly behaving applications. A technician should identify the process responsible before taking corrective action rather than stopping services or uninstalling software randomly. If performance remains poor, additional storage diagnostics may be required.

Question 245.

A user reports that a Windows application opens very slowly after the computer first starts, but performance improves later. Task Manager shows disk utilization at 100% during startup. What should the technician investigate first?

  1. Startup applications and background services
    2. Monitor brightness
    3. DNS suffix
    4. Printer permissions

Correct Answer: 1

Explanation:

If disk utilization is extremely high during startup and then decreases, the technician should investigate applications and services that automatically launch when Windows starts. Antivirus scans, synchronization tools, update agents, indexing services, and numerous startup applications can create heavy disk activity at boot. Task Manager’s Startup section and process utilization views can help identify which items contribute to the load. Monitor brightness, DNS suffix settings, and printer permissions do not explain high local disk usage. The technician should avoid disabling critical security or management software solely to improve startup performance. Instead, unnecessary startup programs can be disabled, legitimate software can be updated, and storage health can be checked if performance remains abnormal.

Question 246.

Which Windows command can display information about currently running processes from the command line?

  1. nslookup
    2. tasklist
    3. chkdsk
    4. gpupdate

Correct Answer: 2

Explanation:

The tasklist command displays a list of processes currently running on a Windows system. It can include process names, process IDs, session information, and memory usage. This is useful in command-line, scripting, or remote troubleshooting scenarios where Task Manager may not be convenient. nslookup queries DNS, chkdsk checks file-system integrity, and gpupdate refreshes Group Policy settings. Once a suspicious or unresponsive process is identified, the technician can investigate it further and, if appropriate, use taskkill to terminate it. However, unfamiliar processes should not be stopped without first determining their purpose because terminating a critical system process or security service can destabilize the computer or weaken protection.

Question 247.

Which Windows command is used to terminate a process when the technician knows its process ID?

  1. netstat
    2. hostname
    3. taskkill
    4. format

Correct Answer: 3

Explanation:

The taskkill command terminates a running Windows process using criteria such as a process ID or image name. It can be useful when an application becomes unresponsive, especially during remote or command-line troubleshooting. netstat displays network connections, hostname shows the computer name, and format prepares a storage volume and can destroy data. Before using taskkill, the technician should confirm that the correct process has been selected and that terminating it will not interrupt a critical service or cause data loss. A forced termination may be necessary for a frozen application, but it should generally be considered after normal closing methods have failed.

Question 248.

A technician wants to view which user account is associated with the current command-line session. Which command should be used?

  1. tracert
    2. ipconfig
    3. route print
    4. whoami

Correct Answer: 4

Explanation:

The whoami command displays the user account under which the current session is running. It is helpful when troubleshooting permissions, remote administration, scripts, or elevation issues because commands may behave differently depending on the security context. Additional switches can provide information about group memberships and privileges. tracert displays network hops, ipconfig shows network configuration, and route print displays the local routing table. Confirming the current user is particularly useful when a technician expects administrative rights but receives access-denied errors. The issue may simply be that the command prompt is running under a standard account or a different identity than expected.

Question 249.

Which Windows command displays the local computer name?

  1. hostname
    2. gpresult
    3. net use
    4. sfc

Correct Answer: 1

Explanation:

The hostname command displays the configured name of the local Windows computer. This is useful when technicians are connected remotely to multiple systems and need to verify the identity of the machine before making changes. gpresult reports applied Group Policy settings, net use manages network resource connections, and sfc checks protected system files. Computer names are also visible through graphical Windows settings, but hostname provides a quick command-line method. Confirming the correct endpoint before running administrative commands is a simple but important practice, especially in environments with similarly configured workstations or servers where accidental changes to the wrong device could cause disruption.

Question 250.

A technician needs to map drive letter Z: to a shared network folder from the command line. Which command is most appropriate?

  1. chkdsk
    2. net use
    3. tasklist
    4. arp -a

Correct Answer: 2

Explanation:

The net use command can create, display, and remove connections to shared network resources. A technician can use it to map a UNC path to a drive letter such as Z:, and credentials can be specified when necessary. This makes it useful for scripts, remote administration, and troubleshooting mapped-drive problems. chkdsk checks disks and file systems, tasklist lists running processes, and arp -a displays local IPv4-to-MAC mappings. If a mapped drive repeatedly fails, the technician should also check network connectivity, DNS, permissions, credentials, and whether the server share is available. Mapping the drive does not override access permissions configured on the server or NTFS file system.

Question 251.

Which Windows security feature controls network traffic by applying inbound and outbound rules to applications, ports, and protocols?

  1. File History
    2. BitLocker
    3. Windows Defender Firewall
    4. System Restore

Correct Answer: 3

Explanation:

Windows Defender Firewall filters network traffic using configured rules that can apply to applications, ports, protocols, network profiles, and other criteria. It helps reduce unauthorized access to the workstation and limits exposure of unnecessary services. File History protects versions of user data, BitLocker encrypts volumes, and System Restore rolls back selected system settings. If an application cannot communicate across the network, the technician should check whether an appropriate firewall rule exists instead of disabling the firewall completely. Permitting only required traffic follows the principle of least privilege. Host firewalls work best when combined with secure network design, endpoint protection, patching, and user authentication controls.

Question 252.

An application needs inbound TCP port 443 to be reachable on a Windows workstation. Which action is most appropriate?

  1. Disable the entire firewall
    2. Create or enable a specific firewall rule allowing the required traffic
    3. Remove all antivirus software
    4. Grant every user local administrator rights

Correct Answer: 2

Explanation:

The correct approach is to configure a specific Windows Defender Firewall rule that permits only the required inbound traffic. Allowing TCP port 443 for the relevant application or profile preserves the rest of the firewall’s protections while enabling the needed service. Disabling the entire firewall exposes all listening services unnecessarily and is not a good troubleshooting or security practice. Removing antivirus software and granting administrator rights are also unrelated and weaken security. The technician should confirm that the application is actually listening on the expected port and that the rule applies to the correct network profile. This approach follows least privilege by permitting only the network access that is required.

Question 253.

Which Windows feature allows selected user files to be encrypted individually on an NTFS volume?

  1. Secure Boot
    2. BitLocker only
    3. Encrypting File System
    4. File History

Correct Answer: 3

Explanation:

Encrypting File System, or EFS, allows individual files and folders on supported NTFS volumes to be encrypted. This is different from BitLocker, which protects an entire volume. EFS can be useful when selected data needs additional confidentiality while the rest of the volume remains unencrypted. Secure Boot protects the startup process, and File History maintains previous versions of user files. Proper certificate and private-key management is critical with EFS because losing the required encryption credentials may make legitimate data recovery impossible. Organizations using EFS should have documented recovery procedures and should ensure that encryption keys are backed up or centrally recoverable according to policy.

Question 254.

Which Windows security technology is designed primarily to encrypt an entire storage volume?

  1. EFS
    2. BitLocker
    3. Windows Sandbox
    4. UAC

Correct Answer: 2

Explanation:

BitLocker provides full-volume encryption for supported Windows editions and is commonly used to protect laptop and desktop drives. It can integrate with TPM hardware and can require additional startup authentication depending on configuration. If a drive is removed from the computer or a laptop is stolen, BitLocker helps protect the stored data against unauthorized offline access. EFS encrypts individual files and folders, Windows Sandbox provides a temporary isolated environment, and User Account Control manages privilege elevation. BitLocker recovery keys should be stored securely in an approved location because they may be needed after hardware changes, TPM issues, firmware updates, or other recovery situations.

Question 255.

Which security concept ensures that information is accessible only to authorized users?

  1. Confidentiality
    2. Availability
    3. Redundancy
    4. Integrity

Correct Answer: 1

Explanation:

Confidentiality is the security objective of preventing unauthorized disclosure of information. Encryption, permissions, authentication, physical security, privacy filters, and secure data handling can all support confidentiality. Availability ensures that systems and information remain accessible when required, while integrity protects against unauthorized or accidental modification. Redundancy may help support availability but is not one of the three main CIA security objectives. Confidentiality is particularly important for passwords, customer records, financial information, personal data, and confidential business documents. Technicians should choose controls based on the sensitivity of the data and should protect information both while stored and while being transmitted.

Question 256.

Which security concept focuses on ensuring that data is not altered without authorization?

  1. Availability
    2. Confidentiality
    3. Redundancy
    4. Integrity

Correct Answer: 4

Explanation:

Integrity means protecting data and systems from unauthorized or unintended modification. Controls such as hashes, digital signatures, file permissions, version control, auditing, and change-management processes can help preserve or verify integrity. Confidentiality focuses on preventing unauthorized disclosure, while availability focuses on keeping systems and data accessible to authorized users. Redundancy can contribute to availability but does not by itself guarantee that data has not been altered. Integrity is especially important for financial records, software packages, configuration files, security logs, and any other information where unauthorized changes could create operational or security consequences. Technicians should consider both preventive and detective controls when protecting data integrity.

Question 257.

Which security concept ensures that authorized users can access required systems and information when needed?

  1. Availability
    2. Confidentiality
    3. Integrity
    4. Obfuscation

Correct Answer: 1

Explanation:

Availability ensures that systems, applications, and information remain accessible to authorized users when required. Controls that support availability include backups, redundant components, failover systems, UPS devices, disaster-recovery planning, clustering, proper capacity management, and protection against denial-of-service conditions. Confidentiality prevents unauthorized disclosure, while integrity protects against unauthorized changes. Obfuscation may make information harder to interpret but is not a core CIA-triad objective. A secure system that is completely unavailable cannot support the organization, so availability is an essential part of information security. Technicians must often balance availability with confidentiality and integrity rather than optimizing one objective while ignoring the others.

Question 258.

Which type of malware often disguises itself as legitimate software in order to trick the user into installing it?

  1. Worm
    2. Trojan
    3. Logic bomb
    4. Rootkit

Correct Answer: 2

Explanation:

A Trojan disguises itself as legitimate, useful, or desirable software in order to convince the user to execute or install it. Once running, it may steal information, install additional malware, establish remote access, or perform other malicious actions. A worm primarily focuses on self-propagation, a logic bomb activates when a specific condition occurs, and a rootkit attempts to hide malicious activity or maintain stealthy privileged access. Software should be obtained only from trusted sources, and users should be cautious with unexpected downloads, cracked applications, or email attachments. Endpoint protection, application control, least privilege, and security awareness can all reduce the risk of Trojan infections.

Question 259.

Which malware type is designed to spread automatically across systems or networks without requiring the user to manually run the malware on every computer?

  1. Adware
    2. Spyware
    3. Worm
    4. Trojan

Correct Answer: 3

Explanation:

A worm is self-propagating malware that can spread automatically between systems, often by exploiting vulnerabilities or weak network services. This makes worms particularly dangerous because they can infect large numbers of devices quickly without depending on a user to launch the malware on each computer. Adware primarily displays unwanted advertisements, spyware gathers information, and Trojans usually depend on users being tricked into executing them. Defenses include rapid patching, network segmentation, endpoint security, firewalls, disabling unnecessary services, and monitoring. If a worm infection is detected, affected systems should be isolated quickly to reduce further propagation while the organization follows its incident-response procedures.

Question 260.

A technician has implemented a fix, confirmed that the original problem is resolved, and verified that the user can complete normal work. What should happen before the support ticket is closed?

  1. Change unrelated settings to prevent unknown future issues
    2. Clear all diagnostic logs
    3. Remove security controls temporarily
    4. Document the findings, actions, and outcomes

Correct Answer: 4

Explanation:

Documentation is the final step after a technician has implemented the solution and verified full system functionality. The record should include the user’s reported symptoms, diagnostic steps, identified cause when known, corrective actions, test results, and preventive recommendations. Accurate documentation helps future technicians recognize recurring problems, improves organizational knowledge, supports accountability, and can assist with trend analysis. Clearing logs or removing security controls can eliminate useful evidence or weaken the system, while unrelated changes may create new problems. A support ticket should therefore be closed only after the solution has been validated and the work has been recorded clearly enough that another technician could understand what happened and how it was resolved.