View Full CompTIA A+ 220-1102 Exam Dumps and Practice Test Dumps
Question 381.
A technician needs to verify whether a Windows workstation can communicate with its default gateway. Which command should be used first?
- ping
2. tasklist
3. gpresult
4. chkdsk
Correct Answer: 1
Explanation:
The ping command is a basic network troubleshooting tool used to test IP connectivity between two devices. If a technician wants to determine whether a workstation can reach its default gateway, pinging the gateway address is a logical first step. A successful response suggests that the local adapter, IP configuration, and Layer 2 path to the gateway are functioning well enough for basic communication. If the gateway does not respond, the technician should verify the workstation’s IP address, subnet mask, physical or wireless connection, VLAN assignment, and whether the gateway permits ICMP responses. tasklist displays running processes, gpresult shows applied Group Policy information, and chkdsk checks disks and file systems. Ping should be interpreted carefully because some systems intentionally block ICMP, so a failed response does not always prove complete loss of connectivity.
Question 382.
A workstation can ping its default gateway but cannot reach a remote web server. Which command is most useful for identifying where the route toward the destination stops?
- hostname
2. tracert
3. sfc /scannow
4. net use
Correct Answer: 2
Explanation:
The tracert command displays the sequence of network hops between a Windows computer and a remote destination. It is useful when local connectivity works but communication to a remote system fails or becomes slow. The technician can compare each hop and identify approximately where traffic stops or latency increases. A missing response at one hop does not automatically indicate a failure because some routers do not respond to traceroute probes while still forwarding traffic normally. hostname displays the local computer name, sfc /scannow checks protected Windows files, and net use manages mapped network resources. Tracert should be used together with ping, DNS testing, routing information, and knowledge of the network topology. The goal is to narrow the location of a connectivity problem rather than assume that the first timeout is the faulty device.
Question 383.
Which Windows command is most appropriate for testing whether a hostname resolves to the expected IP address?
- taskkill
2. diskpart
3. nslookup
4. format
Correct Answer: 3
Explanation:
The nslookup command queries DNS and can show whether a hostname resolves to an expected IP address. It also helps identify which DNS server is answering the query. This is especially useful when a user can reach a resource by IP address but not by name, which strongly suggests a name-resolution problem rather than general network connectivity failure. taskkill terminates processes, diskpart manages disks and partitions, and format prepares a volume for use. If nslookup returns an incorrect address, the technician should investigate DNS records, local configuration, and cached entries. If it cannot reach the DNS server at all, the issue may involve incorrect DNS settings, routing, firewall rules, or network connectivity. Proper DNS testing helps avoid unnecessary changes to unrelated network components.
Question 384.
Which Windows command should a technician use to clear outdated DNS records cached on the local workstation?
- ipconfig /release
2. arp -a
3. route print
4. ipconfig /flushdns
Correct Answer: 4
Explanation:
The ipconfig /flushdns command clears the local Windows DNS resolver cache. This is useful when a hostname has recently changed to a new IP address but the workstation continues using an older cached value. After the cache is cleared, Windows will perform a new DNS query the next time the hostname is requested. ipconfig /release gives up a DHCP lease, arp -a displays the local ARP cache, and route print shows the routing table. Flushing the local cache does not correct an incorrect DNS record stored on the DNS server itself. If the wrong address continues to appear after flushing, the technician should use nslookup to verify the DNS server response and investigate the authoritative record. This step is useful because it addresses stale local information without making broader network changes.
Question 385.
A Windows computer has received an incorrect DHCP configuration. Which command should the technician run first to relinquish the current lease?
- ipconfig /release
2. netstat
3. hostname
4. gpupdate
Correct Answer: 1
Explanation:
The ipconfig /release command gives up the current DHCP lease for applicable Windows network adapters. It is commonly followed by ipconfig /renew to request a fresh configuration from the DHCP server. This sequence can be useful when a workstation has stale or incorrect dynamic addressing information. netstat displays network connections, hostname shows the local machine name, and gpupdate refreshes Group Policy. If the workstation repeatedly receives the wrong address even after renewal, the technician should investigate the DHCP scope, VLAN assignment, unauthorized DHCP servers, relay configuration, or physical network connection. Releasing the lease is only one troubleshooting step and does not fix infrastructure problems. The technician should also document the original network settings before making changes so results can be compared afterward.
Question 386.
Which command should be used after releasing a DHCP lease to request a new one?
- chkdsk
2. ipconfig /renew
3. tasklist
4. nslookup
Correct Answer: 2
Explanation:
The ipconfig /renew command requests a new DHCP lease for supported Windows network adapters. It is usually used after ipconfig /release during troubleshooting of dynamic network configuration. A successful renewal may provide a new IP address, subnet mask, default gateway, DNS servers, and other DHCP options. If renewal fails, the technician should verify that the network adapter has connectivity and that the DHCP server is reachable. Receiving an automatic private address can indicate a failure to contact DHCP. chkdsk checks storage, tasklist lists processes, and nslookup tests DNS resolution. DHCP renewal is useful for refreshing addressing information, but persistent incorrect settings point to a deeper network configuration issue that must be corrected at the source rather than repeatedly renewing the lease.
Question 387.
Which Windows command displays the local routing table, including destination networks, gateways, and route metrics?
- net use
2. gpresult
3. route print
4. whoami
Correct Answer: 3
Explanation:
The route print command displays the Windows IP routing table, including destination networks, subnet masks, gateways, interfaces, and metrics. It is useful when a computer has multiple network adapters, VPN connections, or static routes and traffic is taking an unexpected path. net use manages network resource connections, gpresult shows applied Group Policy, and whoami displays the current user context. A workstation can have a valid IP address and working DNS yet still fail to reach a destination because of an incorrect default route or more specific route. Reviewing the routing table helps isolate this type of problem. Technicians should be cautious when adding or deleting routes because incorrect changes can disrupt access to local or remote networks.
Question 388.
Which Windows command displays the current IP-to-MAC address mappings stored in the ARP cache?
- taskkill
2. gpupdate
3. netstat
4. arp -a
Correct Answer: 4
Explanation:
The arp -a command displays the local Address Resolution Protocol cache, showing mappings between IPv4 addresses and MAC addresses for devices on the same local network. This information can help troubleshoot duplicate addressing, local connectivity issues, or unexpected Layer 2 mappings. taskkill terminates processes, gpupdate refreshes Group Policy, and netstat displays network connections and listening ports. ARP is primarily relevant to local subnet communication. When a destination is on another network, the workstation normally resolves the MAC address of the default gateway rather than the remote host. If an ARP entry appears suspicious or inconsistent, the technician should investigate before making assumptions, because entries can change normally as devices reconnect or addresses are reassigned.
Question 389.
A technician wants to identify which process is listening on a suspicious TCP port. Which command is most useful with the appropriate switches?
- netstat
2. sfc /scannow
3. format
4. gpresult
Correct Answer: 1
Explanation:
The netstat command can display active connections, listening ports, and, with the appropriate option, process IDs associated with those network endpoints. This can help a technician determine which process is responsible for a suspicious listener. Once the process ID is known, tools such as Task Manager or tasklist can be used to identify the executable. sfc /scannow checks protected Windows system files, format prepares storage volumes, and gpresult reports Group Policy information. A listening port is not automatically malicious, because many legitimate applications and services must listen for inbound connections. The technician should identify the process, verify whether it is authorized, review its path and digital signature when appropriate, and investigate further before stopping it or changing firewall rules.
Question 390.
Which Windows command should a technician use to identify the currently logged-in security context before troubleshooting a permissions issue?
- hostname
2. whoami
3. tracert
4. chkdsk
Correct Answer: 2
Explanation:
The whoami command displays the user account under which the current session or command prompt is running. This is especially useful when troubleshooting permission or elevation issues because commands may behave differently depending on the current account, group memberships, and privileges. Additional switches can provide more detailed security information. hostname identifies the computer, tracert displays network hops, and chkdsk checks storage. A technician might believe a command prompt is elevated or that the user is a member of a particular group when that is not actually the case. Verifying the current security context is therefore a simple but effective first step. It prevents unnecessary changes to file permissions or policies when the real issue is simply that the session is running under the wrong identity.
Question 391.
A user reports that access to a shared folder suddenly stopped after a password change. Which Windows feature should a technician inspect for an outdated saved password?
- Disk Cleanup
2. Task Scheduler
3. Credential Manager
4. File History
Correct Answer: 3
Explanation:
Credential Manager stores certain saved usernames and passwords used to access network resources, websites, and other services. If a user’s password changes but a stored credential still contains the old password, Windows may continue attempting authentication with outdated information. This can cause repeated access failures or even account lockouts. Disk Cleanup removes unnecessary files, Task Scheduler automates tasks, and File History stores versions of user files. A technician should identify the credential associated with the affected resource and remove or update it only when authorized. Account lockouts can also come from mapped drives, scheduled tasks, services, or mobile devices, so Credential Manager is an important troubleshooting location but not necessarily the only one. After correcting the credential, access should be retested.
Question 392.
Which Windows security feature is designed to prompt users before software performs actions that require elevated administrative privileges?
- BitLocker
2. EFS
3. Secure Boot
4. User Account Control
Correct Answer: 4
Explanation:
User Account Control, or UAC, helps manage privilege elevation in Windows. When an operation requires administrative rights, UAC can prompt for consent or administrator credentials depending on the current account and configuration. This supports least privilege because users do not need to operate with unrestricted administrative privileges for routine activities. BitLocker provides full-volume encryption, EFS encrypts individual files and folders, and Secure Boot helps verify trusted startup components. UAC is not a substitute for standard user accounts, but it reduces the likelihood that applications can silently make system-wide changes. Disabling UAC to eliminate prompts generally weakens security. A better approach is to use standard accounts and elevate only when a legitimate administrative task requires it.
Question 393.
Which security principle is being applied when a user is granted only the permissions required to perform normal job duties?
- Least privilege
2. Availability
3. Redundancy
4. Obfuscation
Correct Answer: 1
Explanation:
Least privilege means giving users, applications, and services only the permissions necessary to perform their legitimate functions. For example, an employee who only needs to read reports should not be granted Full Control over the folder containing them. This reduces the impact of accidental changes, malware, insider misuse, or stolen credentials. Availability focuses on keeping systems accessible, redundancy helps reduce single points of failure, and obfuscation makes information more difficult to interpret but is not the principle described here. Least privilege should be implemented through role-based access, group permissions, standard user accounts, and controlled privilege elevation. Permissions should also be reviewed periodically because users’ responsibilities can change over time and old access can otherwise accumulate unnecessarily.
Question 394.
Which authentication method requires two or more different factor categories, such as a password and a fingerprint?
- Single sign-on
2. Multifactor authentication
3. Password history
4. Account lockout
Correct Answer: 2
Explanation:
Multifactor authentication, or MFA, requires users to provide authentication from at least two different factor categories. A password is something the user knows, while a fingerprint is something the user is. A hardware security key would be something the user has. Using multiple factors reduces the chance that a stolen password alone can compromise the account. Single sign-on allows one authentication event to provide access to multiple resources but does not necessarily use multiple factors. Password history prevents password reuse, and account lockout limits repeated failed attempts. MFA is especially important for privileged accounts, remote access, cloud services, and sensitive applications. Users should also be trained not to approve unexpected MFA requests or share one-time authentication codes.
Question 395.
A user receives a phone call from someone claiming to be the company’s help desk and asking for the user’s MFA code. Which attack is this?
- Smishing
2. Tailgating
3. Vishing
4. Shoulder surfing
Correct Answer: 3
Explanation:
Vishing is phishing conducted through voice communication, usually telephone calls. Attackers may impersonate help-desk technicians, banks, government agencies, executives, or other trusted individuals and attempt to obtain passwords, MFA codes, financial information, or remote access. Smishing uses text messages, tailgating is a physical access attack, and shoulder surfing involves visually observing confidential information. Users should never provide passwords or one-time authentication codes to unsolicited callers. Instead, they should independently contact the organization through a trusted number or internal support channel. Security awareness is important because vishing attacks exploit trust, urgency, and authority rather than relying entirely on technical vulnerabilities. Organizations should also monitor for unusual authentication attempts following reported social-engineering incidents.
Question 396.
Which social-engineering attack uses fraudulent SMS messages to trick a user into revealing information or clicking a malicious link?
- Phishing by email only
2. Tailgating
3. Vishing
4. Smishing
Correct Answer: 4
Explanation:
Smishing is phishing delivered through SMS or similar text messaging platforms. Attackers commonly impersonate banks, delivery services, employers, security teams, or government agencies and create urgency so that users click links or disclose credentials. The malicious link may lead to a fake login page, malware download, or fraudulent payment request. Vishing uses voice calls, tailgating involves unauthorized physical entry, and phishing by email is a different delivery method. Users should avoid tapping unexpected links and instead open official applications or manually navigate to known websites. Suspicious texts should be reported according to organizational procedures so security teams can investigate whether the campaign is targeting additional employees.
Question 397.
Which malware type disguises itself as legitimate or desirable software in order to trick the user into running it?
- Trojan
2. Worm
3. Rootkit
4. Logic bomb
Correct Answer: 1
Explanation:
A Trojan is malicious software that appears to be legitimate or useful in order to persuade a user to install or execute it. Once active, it may steal data, install additional malware, create remote access, or modify system settings. A worm primarily spreads automatically, a rootkit focuses on hiding malicious activity and maintaining stealthy access, and a logic bomb activates when a specific condition occurs. Trojans often rely on social engineering, so user awareness is an important defense. Organizations should also use application control, endpoint protection, software updates, and least privilege. Software should be downloaded only from trusted sources. If a Trojan is suspected, the affected system may need isolation and investigation under the organization’s malware-response process.
Question 398.
Which malware type is specifically designed to propagate automatically between systems, often by exploiting vulnerabilities?
- Adware
2. Worm
3. Keylogger
4. Trojan
Correct Answer: 2
Explanation:
A worm is self-propagating malware that can spread from one system to another without requiring a user to manually execute it on every device. Worms may exploit vulnerabilities, weak services, or poor network configuration and can spread rapidly across large environments. Adware mainly displays unwanted advertising, a keylogger records keystrokes, and a Trojan relies on deception to get the user to run malicious software. Defenses against worms include timely patching, network segmentation, host firewalls, endpoint security, and disabling unnecessary services. If a worm infection is detected, rapid containment is important because every connected system may become a potential target. Affected systems should be isolated and investigated according to incident-response procedures before being returned to normal network access.
Question 399.
A technician is about to apply a major software update to a production workstation used for critical operations. Which action should be performed before the change?
- Create or verify an appropriate backup and prepare a rollback plan
2. Disable all security controls
3. Delete the existing configuration
4. Apply the update without testing
Correct Answer: 1
Explanation:
Before making a significant production change, the technician should ensure that an appropriate backup or recovery point exists and that a rollback plan has been defined. If the update causes application incompatibility, instability, or other unexpected problems, the rollback procedure provides a controlled method to return to the previous known-good state. Proper change management also includes assessing risk, obtaining approval, testing when practical, communicating the maintenance window, and documenting the change. Disabling security controls or deleting the existing configuration increases risk, while applying an update without testing is inappropriate for a critical workstation. A backup is only useful if it can actually be restored, so organizations should also verify backup health and periodically test recovery procedures.
Question 400.
A technician successfully completes an approved software update, verifies full functionality, and confirms that users can work normally. What should be done before the change is formally closed?
- Disable monitoring temporarily
2. Delete the original change request
3. Make unrelated configuration changes
4. Document the outcome, validation results, and any lessons learned
Correct Answer: 4
Explanation:
After an approved change has been implemented successfully, the final step is to update the change record with the actual outcome. Documentation should include what was changed, whether the expected results were achieved, how functionality was validated, whether any problems occurred, and whether the rollback plan was needed. Any useful lessons learned should also be recorded so future deployments can be improved. Disabling monitoring reduces visibility during the post-change period, deleting the original request destroys the audit trail, and making unrelated changes without approval violates change-control discipline. Proper closure gives the organization a reliable history of production changes and supports troubleshooting, auditing, and operational consistency. A technically successful implementation is not considered fully complete until validation and documentation have also been finished.