CompTIA A+ 220-1102 Practice Test Questions and Exam Dumps Part15 Q281-300

View Full CompTIA A+ 220-1102 Exam Dumps and Practice Test Dumps

 

Question 281.

A Windows user reports that the computer takes a long time to become usable after signing in. Which built-in utility should the technician use first to identify applications that launch automatically at startup?

  1. Task Manager
    2. Disk Management
    3. Event Viewer
    4. Device Manager

Correct Answer: 1

Explanation:

Task Manager includes a Startup section that shows applications configured to launch automatically when a user signs in. It can also indicate the startup impact of many programs, making it easier to identify unnecessary applications that may be slowing the login process. A technician can disable nonessential startup entries without uninstalling the software. Disk Management is used for disks, partitions, and volumes, Event Viewer provides system and application logs, and Device Manager manages hardware and drivers. Startup optimization should be done carefully because security tools, management agents, VPN clients, and other business-critical applications may need to start automatically. After disabling unnecessary entries, the technician should restart the system and verify whether startup performance improves without affecting required functionality.

Question 282.

Which Windows utility should a technician use to determine which processes are consuming the most CPU, memory, disk, or network resources in real time?

  1. File History
    2. Task Manager
    3. System Restore
    4. Local Security Policy

Correct Answer: 2

Explanation:

Task Manager provides real-time visibility into running applications and processes and shows their use of CPU, memory, disk, network, and other resources. A technician can sort by a resource column to identify a process that is consuming an abnormal amount of system capacity. This is especially useful when troubleshooting slow performance, freezing, or excessive fan activity. File History protects previous versions of user files, System Restore rolls back selected system settings, and Local Security Policy controls local security configuration. Resource usage should be interpreted carefully because high utilization can be normal during updates, backups, antivirus scans, or intensive applications. Once a process is identified, the technician should determine whether the behavior is expected, whether the application needs updating, or whether malware or another fault may be involved.

Question 283.

A Windows workstation becomes unresponsive for several minutes each morning. The technician wants a historical view of application failures, Windows failures, and recent updates. Which tool is most appropriate?

  1. Disk Cleanup
    2. Device Manager
    3. Reliability Monitor
    4. Services

Correct Answer: 3

Explanation:

Reliability Monitor presents a timeline of system stability and records important events such as application crashes, Windows failures, hardware errors, driver installations, and software updates. This makes it useful when the problem is intermittent or appears to have started after a recent change. The technician can compare the time of the reported freeze with recorded events and then investigate suspicious items in more detail. Disk Cleanup removes unnecessary files, Device Manager focuses on hardware and driver status, and Services manages background services. Reliability Monitor is not a replacement for Event Viewer, but it provides a clear historical overview that can help narrow the troubleshooting scope. After identifying likely events, the technician can use more detailed logs or vendor information before making changes.

Question 284.

Which Windows utility provides detailed logs for application crashes, service failures, driver problems, and operating-system events?

  1. Disk Management
    2. File Explorer Options
    3. Task Scheduler
    4. Event Viewer

Correct Answer: 4

Explanation:

Event Viewer provides access to Windows logs such as Application, System, Security, and other specialized event channels. Technicians can filter events by time, severity, event source, and event ID to investigate failures and unusual behavior. If an application repeatedly crashes or a service fails during startup, Event Viewer often contains useful diagnostic information recorded at the time of the incident. Disk Management handles storage volumes, File Explorer Options changes how files and folders are displayed, and Task Scheduler automates programs or scripts. Event logs should generally be preserved during troubleshooting because clearing them can remove valuable evidence. A technician should correlate logged events with user reports and recent changes rather than assuming every warning or error listed in Event Viewer is responsible for the problem.

Question 285.

A background Windows service required by a business application is stopped. Which utility should the technician use to start it and review its startup type?

  1. Services
    2. BitLocker
    3. File History
    4. Disk Cleanup

Correct Answer: 1

Explanation:

The Services management console allows technicians to view Windows services, start or stop them, and configure startup behavior such as Automatic, Manual, or Disabled. If a business application depends on a service that is not running, starting the service may restore functionality. The technician should also review service dependencies and Event Viewer logs if the service stops again or fails during startup. BitLocker encrypts storage volumes, File History protects user files, and Disk Cleanup removes unnecessary data. Services should not be disabled randomly because many Windows and application components depend on them. A proper troubleshooting process identifies why the service stopped and whether the startup configuration, credentials, dependencies, or application installation need correction.

Question 286.

Which Windows utility should be used to create a scheduled task that launches a backup script every night at 11:00 PM?

  1. Device Manager
    2. Task Scheduler
    3. System Restore
    4. Disk Management

Correct Answer: 2

Explanation:

Task Scheduler allows administrators to configure applications, scripts, and other actions to run automatically based on triggers. A trigger can specify an exact time, a repeating schedule, system startup, user logon, or an event. For a nightly backup script, the technician can create a daily trigger at 11:00 PM and configure the appropriate executable or script as the action. Device Manager manages hardware and drivers, System Restore rolls back selected system configuration changes, and Disk Management handles disks and volumes. Scheduled tasks should be tested after creation to ensure that the correct account, permissions, paths, and conditions are configured. A script that runs manually may still fail when scheduled if it depends on interactive user access or unavailable network resources.

Question 287.

A technician needs to see detailed network settings including the workstation’s IP address, subnet mask, default gateway, DHCP server, and DNS server addresses. Which command should be used?

  1. nslookup
    2. netstat
    3. ipconfig /all
    4. tasklist

Correct Answer: 3

Explanation:

The ipconfig /all command displays detailed TCP/IP configuration for Windows network adapters. It can show IPv4 and IPv6 addresses, subnet masks, default gateways, DNS servers, DHCP status, DHCP server information, lease details, and the adapter’s physical address. This makes it one of the most useful first commands when troubleshooting network configuration. nslookup focuses on DNS queries, netstat displays active network connections and listening ports, and tasklist lists running processes. The technician should compare the displayed settings with the expected network configuration. An incorrect gateway, DNS address, subnet, or DHCP assignment can produce different symptoms, so accurately identifying the existing configuration helps avoid unnecessary changes.

Question 288.

Which command should a technician use to request a new DHCP lease after the existing lease has been released?

  1. arp -a
    2. gpupdate
    3. route print
    4. ipconfig /renew

Correct Answer: 4

Explanation:

The ipconfig /renew command requests a new DHCP lease for applicable Windows network adapters. It is commonly used after ipconfig /release, which relinquishes the existing dynamic address. Renewing the lease can help when the workstation has outdated or incorrect DHCP-provided network configuration. arp -a displays the ARP cache, gpupdate refreshes Group Policy settings, and route print displays the routing table. If the workstation cannot obtain a lease, the technician should investigate whether the network adapter has link connectivity, whether the system is on the correct VLAN, whether the DHCP server is reachable, or whether the DHCP scope has available addresses. Repeated renewal attempts will not solve an underlying network or DHCP infrastructure problem.

Question 289.

A workstation can reach a server by IP address but not by hostname. Which command should the technician use first to test name resolution?

  1. nslookup
    2. chkdsk
    3. taskkill
    4. diskpart

Correct Answer: 1

Explanation:

The nslookup command queries DNS and can determine whether a hostname resolves to the expected IP address. If the server is reachable directly by IP, basic network connectivity is functioning, so name resolution becomes the more likely area of investigation. nslookup also helps identify which DNS server is responding. chkdsk checks disk and file-system integrity, taskkill terminates processes, and diskpart manages storage. If nslookup fails, the technician should check the DNS configuration using ipconfig /all, verify that the DNS server is reachable, and confirm that the correct DNS record exists. If the record was recently changed, clearing the local DNS cache may also be useful.

Question 290.

Which Windows command clears stale DNS entries stored in the local resolver cache?

  1. net use
    2. ipconfig /flushdns
    3. hostname
    4. tasklist

Correct Answer: 2

Explanation:

The ipconfig /flushdns command clears the local Windows DNS resolver cache. This is useful when a workstation continues using an old IP address for a hostname after a DNS record has been updated. Once the cache is cleared, Windows must request fresh DNS information the next time the hostname is accessed. net use manages connections to shared network resources, hostname displays the computer name, and tasklist lists running processes. Flushing the local cache does not correct an incorrect record stored on the DNS server itself. If name resolution continues to fail, the technician should use nslookup, verify the configured DNS servers, and investigate the authoritative DNS record.

Question 291.

Which command shows the intermediate network hops between a Windows workstation and a remote host?

  1. ipconfig
    2. tasklist
    3. tracert
    4. sfc

Correct Answer: 3

Explanation:

The tracert command displays the network path toward a destination by showing intermediate routers, or hops. It can help identify where traffic stops or where high latency begins. This is useful when the workstation can communicate locally but cannot reliably reach a remote system across multiple routed networks. ipconfig shows local network configuration, tasklist displays processes, and sfc checks protected Windows system files. Some routers may intentionally not respond to traceroute probes, so a timeout at one hop does not automatically indicate a fault. The technician should interpret traceroute results alongside ping tests, DNS results, routing information, and knowledge of the expected network topology.

Question 292.

Which Windows command displays active network connections and listening ports and can also show process IDs with the appropriate option?

  1. chkdsk
    2. gpresult
    3. net use
    4. netstat

Correct Answer: 4

Explanation:

The netstat command displays information about active network connections and listening ports. Depending on the switches used, it can also show numerical addresses, routing details, and process IDs associated with connections. This is useful when troubleshooting whether a service is actually listening on an expected port or when investigating suspicious network activity. chkdsk checks disks and file systems, gpresult reports applied Group Policy, and net use manages network resource connections. A listening port is not necessarily a security problem because many legitimate services must listen for connections. If an unexpected port appears, the technician should identify the associated process and determine whether it is authorized before terminating it or changing firewall rules.

Question 293.

A technician needs to identify which account is running the current Windows command prompt. Which command is most appropriate?

  1. whoami
    2. hostname
    3. tracert
    4. format

Correct Answer: 1

Explanation:

The whoami command displays the account under which the current command-line session is running. This is useful when troubleshooting permissions, remote sessions, scripts, or administrative elevation. Additional options can display group memberships and privileges. hostname identifies the computer rather than the user, tracert displays network hops, and format prepares a volume and can erase existing data. A technician may expect a command to run with administrative privileges but receive an access-denied message because the session is running under a standard account or because the command prompt was not elevated. Verifying the current security context is therefore a simple and useful troubleshooting step before making further permission changes.

Question 294.

Which Windows command allows a technician to map or remove connections to shared network folders?

  1. taskkill
    2. net use
    3. chkdsk
    4. arp -a

Correct Answer: 2

Explanation:

The net use command can create, view, and remove connections to shared network resources. It is commonly used to map a UNC path to a drive letter or disconnect an existing mapped drive. Credentials may also be specified when permitted and necessary. taskkill terminates processes, chkdsk checks disks and file-system integrity, and arp -a shows the local ARP cache. If a mapped share does not work, the technician should verify connectivity, DNS resolution, share availability, user credentials, share permissions, and NTFS permissions. Mapping a drive letter does not override access controls configured on the server, so successful mapping still depends on the user having appropriate authorization.

Question 295.

Which Windows security feature encrypts an entire drive and can work with TPM hardware to protect encryption keys?

  1. Secure Boot
    2. EFS
    3. BitLocker
    4. Windows Sandbox

Correct Answer: 3

Explanation:

BitLocker provides full-volume encryption for supported Windows systems and can use TPM hardware to help protect encryption keys and validate parts of the startup environment. This is especially useful for laptops and other portable systems where physical theft could otherwise expose stored data. Secure Boot helps verify trusted startup components, EFS provides file-level encryption, and Windows Sandbox creates a temporary isolated environment. BitLocker recovery keys must be stored securely because they may be required after certain firmware changes, TPM issues, or other recovery events. Encryption protects the confidentiality of data at rest but does not replace authentication, endpoint security, backups, or proper access controls once the operating system has been unlocked.

Question 296.

Which Windows technology should be used when only selected files and folders on an NTFS volume need encryption?

  1. BitLocker
    2. Secure Boot
    3. UAC
    4. EFS

Correct Answer: 4

Explanation:

Encrypting File System, or EFS, provides file- and folder-level encryption on supported NTFS volumes. This makes it appropriate when only selected data needs to be encrypted rather than the entire volume. BitLocker encrypts whole volumes, Secure Boot protects the startup process, and User Account Control manages privilege elevation. EFS depends on user certificates and private keys, so key management and recovery planning are essential. If the encryption certificate and private key are lost and no recovery mechanism exists, authorized users may lose access to the files permanently. Organizations should therefore ensure that EFS is used according to policy and that certificates are backed up or recoverable through approved administrative procedures.

Question 297.

Which security control best reduces the chance that a stolen password alone can be used to access an account?

  1. Multifactor authentication
    2. Password history only
    3. Screen resolution policy
    4. File compression

Correct Answer: 1

Explanation:

Multifactor authentication requires users to present two or more independent authentication factors, such as a password and a hardware token or biometric factor. If an attacker steals the password, the additional factor may still prevent unauthorized access. Password history prevents immediate reuse of old passwords but does not protect against current password theft. Screen resolution and file compression are unrelated to authentication. MFA is particularly important for administrator accounts, remote access, cloud services, and sensitive systems. Users should also be trained not to approve unexpected authentication prompts or share one-time codes because attackers may use social engineering to bypass the benefits of MFA.

Question 298.

Which type of social-engineering attack uses SMS messages to trick victims into clicking malicious links or revealing credentials?

  1. Tailgating
    2. Smishing
    3. Vishing
    4. Shoulder surfing

Correct Answer: 2

Explanation:

Smishing is phishing performed through SMS or similar text messaging services. Attackers often impersonate delivery companies, banks, employers, government agencies, or technical support and create urgency to encourage victims to click a malicious link. The link may lead to a fake login page, malware download, or fraudulent payment request. Tailgating is a physical access attack, vishing uses voice calls, and shoulder surfing involves visually observing sensitive information. Users should avoid opening unexpected links and should access services through official applications or independently entered websites. Suspicious text messages should also be reported according to organizational security procedures so other users can be warned if the campaign is widespread.

Question 299.

Which type of malware is designed to hide itself or other malicious components while maintaining privileged access to a system?

  1. Adware
    2. Spyware
    3. Rootkit
    4. Worm

Correct Answer: 3

Explanation:

A rootkit is designed to conceal malicious activity and may maintain privileged or persistent access to a compromised system. Rootkits can operate at different levels, including the operating system or boot process, and may interfere with normal security tools. Adware primarily displays unwanted advertisements, spyware gathers information, and worms focus on self-propagation. Because a rootkit can undermine trust in the operating system itself, simple malware removal may not always be sufficient. Depending on organizational policy and the sensitivity of the system, technicians may need offline scanning, trusted recovery media, or a complete reimage from known-good sources. Any affected credentials should also be considered potentially compromised and handled according to incident-response procedures.

Question 300.

A technician has removed malware from a workstation, installed missing updates, verified that security software is active, and confirmed that all normal functions work. What should be done before the incident is closed?

  1. Disable the firewall to prevent future conflicts
    2. Delete all event logs
    3. Remove the user’s password
    4. Document the findings, actions taken, results, and preventive measures

Correct Answer: 4

Explanation:

Documentation is the final step after the technician has implemented a solution and verified full system functionality. For a malware incident, the support record should include the original symptoms, containment actions, malware-removal steps, updates installed, configuration changes, verification results, and any recommendations intended to prevent recurrence. This documentation helps future technicians, supports security investigations, enables trend analysis, and provides accountability. Disabling the firewall or removing authentication would weaken the system, while deleting event logs could destroy valuable evidence. A complete record should be clear enough that another technician can understand what happened and what was done. Once documentation is complete and the user confirms normal operation, the incident can be closed according to organizational procedures.