View Full CompTIA A+ 220-1102 Exam Dumps and Practice Test Dumps
Question 101.
A Windows user reports that a recently installed application is causing system instability. The technician wants to remove the application without affecting unrelated files. Which Windows utility is most appropriate?
- Apps and Features
2. Disk Management
3. Event Viewer
4. Device Manager
Correct Answer: 1
Explanation:
Apps and Features, or the equivalent installed-apps management interface in Windows, is designed to uninstall applications cleanly. It allows the technician to remove the problematic software without making unnecessary changes to storage partitions, hardware drivers, or system logs. Disk Management is used for volumes and partitions, Event Viewer displays diagnostic logs, and Device Manager manages hardware and drivers. Removing a recently installed application is a logical troubleshooting step when the timing of the instability strongly correlates with that installation. After uninstalling it, the technician should verify that system stability has returned.
Question 102.
Which Windows feature allows an administrator to install optional Windows components such as legacy services or management features?
- Task Scheduler
2. Turn Windows features on or off
3. Disk Cleanup
4. Reliability Monitor
Correct Answer: 2
Explanation:
The Turn Windows features on or off interface allows administrators to enable or disable optional operating-system components. These can include legacy technologies, management tools, virtualization-related features, and other Windows capabilities depending on the edition. Task Scheduler automates tasks, Disk Cleanup removes unnecessary files, and Reliability Monitor displays historical stability information. Optional features should be enabled only when needed because unnecessary components can increase system complexity and potentially expand the attack surface. Administrators should also understand whether a feature has additional dependencies before making changes.
Question 103.
A technician wants to determine whether an application crash began immediately after a specific Windows update was installed. Which utility provides a useful timeline of reliability events?
- Device Manager
2. Services
3. Reliability Monitor
4. Disk Management
Correct Answer: 3
Explanation:
Reliability Monitor presents a historical timeline of important system events such as application failures, Windows failures, updates, and hardware-related problems. It is particularly useful when a technician needs to correlate the start of instability with a recent software installation or Windows update. Device Manager focuses on hardware and drivers, Services manages background services, and Disk Management handles disks and volumes. Reliability Monitor provides a high-level view of system stability over time and can help narrow the troubleshooting scope before more detailed Event Viewer investigation.
Question 104.
Which Windows tool should a technician use to configure whether a particular program is allowed through the host firewall?
- Device Manager
2. File History
3. Disk Management
4. Windows Defender Firewall
Correct Answer: 4
Explanation:
Windows Defender Firewall allows administrators to control inbound and outbound network communication using rules. A technician can permit a specific application or service through the firewall rather than disabling the firewall entirely. This follows the principle of least privilege by allowing only the network communication that is required. Device Manager handles hardware, File History protects user files, and Disk Management manages storage. When troubleshooting an application that works locally but fails to communicate across the network, checking the relevant firewall rule is more appropriate than turning off host-based protection.
Question 105.
Which Windows command forces the local computer to immediately refresh applicable Group Policy settings?
- gpupdate
2. gpresult
3. netstat
4. arp -a
Correct Answer: 1
Explanation:
The gpupdate command refreshes Group Policy settings for the computer and user. This can be useful after administrators make policy changes and want the workstation to process them without waiting for the normal background refresh cycle. gpresult reports which policies have been applied but does not itself trigger the refresh. netstat displays network connections, while arp -a shows local ARP cache entries. When troubleshooting whether a policy change has reached a device, technicians may use gpupdate followed by gpresult to verify the effective configuration.
Question 106.
Which Windows command provides information about the Group Policy objects and settings currently applied to a user or computer?
- chkdsk
2. gpresult
3. hostname
4. taskkill
Correct Answer: 2
Explanation:
The gpresult command reports the Group Policy settings that apply to the current system or user. It is useful when troubleshooting why a security, desktop, software, or networking policy is not behaving as expected. Depending on the options used, it can provide increasingly detailed information about policy processing. chkdsk checks file-system integrity, hostname displays the machine name, and taskkill terminates a process. Group Policy troubleshooting often involves first refreshing policies with gpupdate and then using gpresult to confirm what was actually applied.
Question 107.
A technician needs to determine which Windows process is associated with a suspicious process ID. Which command is most appropriate?
- nslookup
2. net use
3. tasklist
4. format
Correct Answer: 3
Explanation:
The tasklist command displays processes currently running on Windows and includes information such as process identifiers. This can help a technician map a suspicious PID to the corresponding executable or application. Once the process has been identified, further investigation can determine whether it is legitimate or malicious. nslookup queries DNS, net use manages shared network resources, and format prepares a volume for use. Technicians should avoid terminating unfamiliar processes until they understand their purpose because stopping a critical Windows component can destabilize the system.
Question 108.
Which command can terminate a Windows process when the technician knows its process ID?
- ipconfig
2. sfc
3. hostname
4. taskkill
Correct Answer: 4
Explanation:
The taskkill command is used to terminate processes from the Windows command line. A technician can specify a process ID or executable name and can use appropriate options when a process does not close normally. This is useful in remote support, scripting, or situations where the graphical Task Manager is unavailable. ipconfig displays network configuration, sfc checks protected system files, and hostname displays the local computer name. Technicians should confirm the correct process before using taskkill because terminating the wrong process can interrupt critical services or user work.
Question 109.
Which Windows command is used to display the currently logged-in user’s identity?
- whoami
2. tracert
3. chkdsk
4. netstat
Correct Answer: 1
Explanation:
The whoami command displays the user account under which the current session or command prompt is running. This is valuable when troubleshooting permissions, remote sessions, scripts, or privilege-elevation issues because the technician can quickly confirm the actual security context. Additional options can display group memberships and privileges. tracert traces a network path, chkdsk checks disks, and netstat displays network connections. Verifying identity is particularly useful when commands behave differently under standard and administrative accounts.
Question 110.
Which Windows command displays the local computer name from a command prompt?
- tasklist
2. hostname
3. gpupdate
4. nslookup
Correct Answer: 2
Explanation:
The hostname command displays the configured name of the local computer. It is useful when working across multiple command-line sessions, remote support connections, or scripts where a technician must verify which device is being managed. tasklist lists running processes, gpupdate refreshes Group Policy, and nslookup performs DNS queries. A computer name is also visible through graphical Windows settings, but hostname provides a fast command-line method. Confirming the correct machine before making administrative changes is a useful operational habit.
Question 111.
Which type of malware is specifically designed to display unwanted advertisements, often in browsers or applications?
- Rootkit
2. Worm
3. Adware
4. Logic bomb
Correct Answer: 3
Explanation:
Adware is software that displays unwanted or intrusive advertising, often through browser pop-ups, redirected searches, injected advertisements, or bundled applications. Some adware is merely annoying, while more aggressive forms may track behavior or expose users to additional security risks. A rootkit focuses on stealth and privileged persistence, a worm spreads automatically between systems, and a logic bomb activates when a predefined condition occurs. Users should install software only from trusted sources and carefully review bundled installation options to reduce the risk of unwanted adware.
Question 112.
Which type of malware is designed to collect information about a user’s activity without permission?
- Ransomware
2. Worm
3. Trojan
4. Spyware
Correct Answer: 4
Explanation:
Spyware secretly gathers information about users or systems. It may monitor browsing habits, collect credentials, capture personal data, or transmit system information to an attacker. Ransomware focuses on denying access to systems or data, worms spread automatically, and Trojans disguise themselves as legitimate software. Spyware can sometimes be bundled with apparently harmless applications, so endpoint protection, software patching, least privilege, browser security, and user awareness are important defenses. Systems suspected of spyware infection should be investigated and cleaned using established malware-remediation procedures.
Question 113.
A user receives a text message claiming to be from a bank and is instructed to click a link to verify the account. Which social-engineering attack is this?
- Smishing
2. Tailgating
3. Shoulder surfing
4. Dumpster diving
Correct Answer: 1
Explanation:
Smishing is phishing conducted through SMS or other text messaging services. Attackers may impersonate banks, delivery companies, government agencies, or employers and pressure users to click malicious links or disclose sensitive information. Tailgating is a physical access attack, shoulder surfing involves observing confidential information, and dumpster diving involves searching discarded materials. Users should avoid clicking unexpected links in text messages and instead access legitimate services through trusted applications or known websites. Suspicious messages should be reported according to organizational security procedures.
Question 114.
Which social-engineering technique uses a telephone or voice call to trick a victim into revealing sensitive information?
- Phishing only
2. Vishing
3. Tailgating
4. Shoulder surfing
Correct Answer: 2
Explanation:
Vishing is voice-based phishing. Attackers may pretend to be help-desk technicians, financial institutions, government officials, or other trusted parties and attempt to obtain passwords, verification codes, payment details, or remote access. Phishing is the broader category often associated with email, while tailgating and shoulder surfing are physical techniques. Users should independently verify unexpected callers through trusted contact information and should never disclose passwords or multifactor authentication codes to unsolicited callers. Help-desk policies should reinforce that legitimate administrators do not need users to reveal passwords.
Question 115.
Which physical attack occurs when an attacker observes a user’s screen or keyboard to obtain a password?
- Whaling
2. Vishing
3. Shoulder surfing
4. Smishing
Correct Answer: 3
Explanation:
Shoulder surfing occurs when an attacker physically observes a user’s screen, keyboard, or other information source to capture sensitive information. It can occur in offices, coffee shops, airports, public transportation, or other shared environments. Privacy filters, careful screen positioning, user awareness, and secure entry practices can reduce the risk. Whaling is targeted phishing against high-value individuals, vishing uses voice calls, and smishing uses text messages. Even strong technical security can be undermined if sensitive information is exposed through careless physical handling.
Question 116.
Which physical access control is designed to reduce tailgating by allowing only one person to pass through a controlled entrance at a time?
- Privacy filter
2. Cable lock
3. UPS
4. Mantrap
Correct Answer: 4
Explanation:
A mantrap uses two controlled doors to restrict access so that a person normally must complete authentication and enter the secure space individually. The second door remains locked until the first is secured, reducing opportunities for tailgating. Privacy filters protect displayed information, cable locks help prevent device theft, and an uninterruptible power supply protects equipment from certain power interruptions. Mantraps are commonly used in high-security facilities, data centers, and other areas where stronger physical access control is required.
Question 117.
Which security practice requires sensitive company information to be stored only in approved locations and disposed of according to organizational policy?
- Data handling policy
2. Open permissions
3. Shared administrator accounts
4. Default passwords
Correct Answer: 1
Explanation:
A data handling policy defines how organizational information should be classified, stored, transmitted, accessed, retained, and disposed of. Sensitive information may require encryption, restricted storage locations, secure transfer methods, and approved destruction procedures. Open permissions, shared administrator accounts, and default passwords weaken security rather than establish proper information handling. Employees and technicians should understand the classification level of the data they work with and follow organizational requirements throughout the data lifecycle, including when devices or media are reassigned or discarded.
Question 118.
Which security concept ensures that information has not been altered without authorization?
- Availability
2. Integrity
3. Confidentiality
4. Redundancy
Correct Answer: 2
Explanation:
Integrity means protecting information and systems from unauthorized or unintended modification. Controls such as hashes, digital signatures, access permissions, change management, and auditing can help detect or prevent unauthorized changes. Confidentiality focuses on preventing unauthorized disclosure, while availability ensures that systems and data remain accessible when required. Redundancy can support availability but is not one of the three core CIA-triad principles. Integrity is especially important for software, financial records, configuration files, and other data where unauthorized modification could cause significant operational or security consequences.
Question 119.
Which security principle ensures that authorized users can access systems and data when needed?
- Confidentiality
2. Integrity
3. Availability
4. Obfuscation
Correct Answer: 3
Explanation:
Availability means ensuring that systems, services, and information remain accessible to authorized users when required. Technologies such as redundancy, backups, failover systems, UPS devices, clustering, and disaster-recovery planning can help support availability. Confidentiality protects information from unauthorized disclosure, while integrity protects against unauthorized modification. Obfuscation may make information harder to interpret but is not a core CIA-triad principle. Availability is critical because even perfectly confidential and accurate data provides little business value if authorized users cannot access it when needed.
Question 120.
A technician has resolved a workstation issue, tested the solution, and verified with the user that normal operation has been restored. What is the final step in the standard troubleshooting process?
- Change additional unrelated settings
2. Delete all diagnostic logs
3. Recreate the problem intentionally
4. Document findings, actions, and outcomes
Correct Answer: 4
Explanation:
Documentation is the final step after a technician has implemented the solution and verified full functionality. The support record should include the original symptoms, troubleshooting steps, identified cause, corrective action, results, and any preventive recommendations. Accurate documentation helps other technicians resolve similar incidents, provides accountability, supports trend analysis, and creates useful organizational knowledge. Deleting diagnostic information or changing unrelated settings after successful resolution can create unnecessary risk. A well-documented ticket allows the issue to be closed confidently and provides a clear history if the problem later returns.