CompTIA A+ 220-1102 Practice Test Questions and Exam Dumps Part9 Q161-180

View Full CompTIA A+ 220-1102 Exam Dumps and Practice Test Dumps

 

Question 161.

A Windows workstation is running slowly, and the technician suspects one process is consuming excessive processor resources. Which built-in tool should be used first to identify the process?

  1. Task Manager
    2. Disk Management
    3. File Explorer Options
    4. Local Security Policy

Correct Answer: 1

Explanation:

Task Manager provides a real-time view of running applications and background processes and shows how much CPU, memory, disk, network, and other resources each process is consuming. A technician can sort the process list by CPU usage to quickly identify an application or service that is placing unusual load on the processor. Disk Management handles disks, partitions, and volumes rather than process performance. File Explorer Options controls how files and folders are displayed, while Local Security Policy manages security-related settings such as account and audit policies. After identifying the process, the technician should determine whether it is legitimate, whether it can be closed safely, and whether an update, configuration change, or malware investigation is required.

Question 162.

Which Windows utility presents a historical timeline of application failures, Windows failures, and other events that can help correlate a problem with a recent change?

  1. Device Manager
    2. Reliability Monitor
    3. Disk Cleanup
    4. Windows Firewall

Correct Answer: 2

Explanation:

Reliability Monitor provides a graphical timeline showing system stability over time. It records events such as application crashes, Windows failures, hardware errors, driver installations, and software updates. This is particularly useful when a user says a system “started acting up a few days ago” because the technician can identify what changed around the same time the issue began. Device Manager focuses on hardware and drivers, Disk Cleanup removes unnecessary files, and Windows Firewall controls network traffic. Reliability Monitor provides a summarized historical view that can help narrow the troubleshooting scope before the technician examines more detailed logs in Event Viewer or changes any system configuration.

Question 163.

A Windows application crashes at the same time every day. Which utility should a technician use to review detailed application error events?

  1. Task Scheduler
    2. Disk Management
    3. Event Viewer
    4. BitLocker

Correct Answer: 3

Explanation:

Event Viewer stores detailed logs for Windows, applications, security events, and other components. If an application crashes at a predictable time, the technician can review the Application log around that timestamp and look for error events, event IDs, faulting modules, or related service failures. Task Scheduler may be relevant if a scheduled task triggers the problem, but Event Viewer is the most direct tool for reviewing the crash itself. Disk Management is used for storage administration, while BitLocker provides full-volume encryption. Event Viewer is especially valuable for recurring problems because it preserves historical records that can be compared across multiple failures.

Question 164.

Which Windows utility is most appropriate for creating a task that launches a maintenance script every Friday evening?

  1. Services
    2. Device Manager
    3. System Restore
    4. Task Scheduler

Correct Answer: 4

Explanation:

Task Scheduler allows administrators to create automated tasks that run according to defined triggers. A task can start at a specific time, on a recurring schedule, when a user logs on, at system startup, or when certain events occur. It can then launch a script, application, or other supported action. Services manages background services rather than general scheduled automation. Device Manager handles hardware and drivers, while System Restore rolls back certain system configuration changes. Task Scheduler is therefore the correct Windows utility when a technician needs to automate a maintenance script at a recurring time such as every Friday evening.

Question 165.

A technician wants to stop a Windows service temporarily to determine whether it is causing a software conflict. Which utility should be used?

  1. Services
    2. File History
    3. Disk Cleanup
    4. Storage Spaces

Correct Answer: 1

Explanation:

The Services management console allows a technician to view services, stop or start them, restart them, and configure how they start with Windows. Temporarily stopping a suspected service can help determine whether that service is involved in a software conflict. Before doing so, the technician should understand the service’s purpose and dependencies because stopping critical services can disrupt operating-system or application functionality. File History protects user files, Disk Cleanup removes unnecessary data, and Storage Spaces provides storage pooling and resiliency. The Services console is therefore the appropriate tool for testing whether a background service is contributing to an issue.

Question 166.

Which Windows command displays detailed network configuration, including the DHCP server and DNS server addresses assigned to an adapter?

  1. ping
    2. ipconfig /all
    3. tasklist
    4. sfc /scannow

Correct Answer: 2

Explanation:

The ipconfig /all command provides detailed TCP/IP configuration information for Windows network adapters. It can display the IP address, subnet mask, default gateway, DHCP status, DHCP server, DNS server addresses, lease information, and the adapter’s physical address. This makes it one of the first commands a technician should use when troubleshooting incorrect network settings. ping tests basic connectivity, tasklist displays running processes, and sfc /scannow checks protected Windows system files. If a workstation is receiving the wrong network configuration, ipconfig /all helps determine whether DHCP and DNS settings are being assigned as expected.

Question 167.

A Windows workstation has a valid IP address but cannot resolve a known server name. Which command should the technician use to test DNS resolution directly?

  1. netstat
    2. hostname
    3. nslookup
    4. chkdsk

Correct Answer: 3

Explanation:

nslookup queries DNS and can show whether a hostname resolves to an IP address and which DNS server is responding. If the workstation already has valid IP connectivity but cannot reach systems by name, DNS is a likely area to investigate. A technician can compare results using the configured DNS server and, when appropriate, another known DNS server to help isolate the issue. netstat displays connections and listening ports, hostname displays the local computer’s name, and chkdsk checks disks and file systems. nslookup is therefore the most appropriate command for directly investigating name-resolution problems.

Question 168.

A technician suspects that a Windows computer has an incorrect cached DNS entry. Which command should be used to remove locally cached DNS records?

  1. ipconfig /release
    2. arp -a
    3. route print
    4. ipconfig /flushdns

Correct Answer: 4

Explanation:

The ipconfig /flushdns command clears the Windows DNS resolver cache. This is useful when the computer may have stored an outdated or incorrect DNS record, such as after a server IP address was recently changed. Once the cache is cleared, the next request for that hostname must be resolved again using the configured DNS server. ipconfig /release releases a DHCP lease, arp -a displays local IP-to-MAC mappings, and route print shows the routing table. Flushing the DNS cache changes only the locally cached name-resolution information and does not change the configured DNS server addresses themselves.

Question 169.

A Windows workstation has received an incorrect DHCP configuration. Which sequence is most appropriate for requesting a fresh lease?

  1. ipconfig /release followed by ipconfig /renew
    2. nslookup followed by tracert
    3. sfc followed by chkdsk
    4. netstat followed by taskkill

Correct Answer: 1

Explanation:

ipconfig /release gives up the current DHCP lease, and ipconfig /renew requests a new lease from the DHCP server. This sequence can help when the workstation has stale or incorrect dynamically assigned network settings. The technician should still investigate further if the computer repeatedly receives an incorrect address because the root cause may involve DHCP scope configuration, VLAN placement, a rogue DHCP server, or network connectivity. nslookup and tracert are network diagnostic tools but do not renew DHCP configuration. sfc, chkdsk, netstat, and taskkill address entirely different operating-system or process-management tasks.

Question 170.

Which command should a technician use to display the path packets take from a Windows workstation to a remote destination?

  1. tasklist
    2. tracert
    3. gpupdate
    4. format

Correct Answer: 2

Explanation:

The tracert command displays the sequence of network hops between the Windows computer and a destination. It can help identify where connectivity fails or where significant latency begins. This is particularly useful when local networking works but a remote resource across several routers cannot be reached reliably. Not every router is required to respond to traceroute-style probes, so missing responses do not always indicate a failure. tasklist displays processes, gpupdate refreshes Group Policy, and format prepares a storage volume. Tracert is therefore the appropriate command for examining the route through an IP network.

Question 171.

Which Windows command is useful for checking whether a specific local service is listening on a TCP or UDP port?

  1. gpresult
    2. hostname
    3. netstat
    4. diskpart

Correct Answer: 3

Explanation:

The netstat command can display active network connections and listening ports. With suitable options, it can also show numerical addresses and process identifiers, helping a technician associate a listening port with a process. This is useful when troubleshooting whether an application server or local service is actually listening for connections. gpresult reports Group Policy information, hostname displays the machine name, and diskpart is a storage-management command-line utility. Netstat is therefore valuable for diagnosing connection problems, identifying open listeners, and investigating unexpected network activity on a Windows system.

Question 172.

Which Windows command shows the contents of the local ARP cache?

  1. ipconfig /all
    2. net use
    3. nslookup
    4. arp -a

Correct Answer: 4

Explanation:

The arp -a command displays the local Address Resolution Protocol cache, which contains mappings between IPv4 addresses and MAC addresses learned on the local network. This can be useful when troubleshooting communication with devices on the same subnet or investigating whether the workstation has learned an unexpected hardware address for a destination. ipconfig /all provides adapter configuration, net use manages connections to shared resources, and nslookup tests DNS resolution. ARP operates between IP and Ethernet addressing on the local network, so the ARP cache is particularly relevant to local-subnet connectivity problems.

Question 173.

A user’s Windows computer repeatedly locks the account because an old password is still being used by a mapped network resource. Which command can help a technician review or remove mapped network connections?

  1. net use
    2. sfc
    3. taskkill
    4. route print

Correct Answer: 1

Explanation:

The net use command displays, creates, and removes connections to network shares. If a mapped drive or resource is still attempting to authenticate with obsolete credentials, a technician can inspect existing mappings and remove or recreate the connection as appropriate. This can help resolve repeated account lockouts caused by stored or stale network authentication attempts. sfc validates protected Windows system files, taskkill terminates processes, and route print displays routing information. Account lockouts can also come from services, scheduled tasks, mobile devices, or cached credentials, so the technician should continue investigating if the problem persists.

Question 174.

A company’s security policy requires each user to have a unique account rather than sharing a single department login. What is the primary security benefit?

  1. Faster file transfers
    2. Improved accountability
    3. Increased display resolution
    4. Reduced disk fragmentation

Correct Answer: 2

Explanation:

Unique user accounts improve accountability because actions can be associated with a specific individual. This supports auditing, incident investigation, access control, and proper offboarding. Shared accounts make it difficult to determine who performed an action and often lead to password sharing, which increases security risk. Unique accounts also allow administrators to assign permissions according to job roles and revoke one person’s access without affecting everyone else. File-transfer performance, display resolution, and disk fragmentation are unrelated to account identity. In addition to unique accounts, organizations should use strong authentication, least privilege, and appropriate logging to maintain effective access control.

Question 175.

Which security principle requires administrators to grant users only the minimum permissions necessary to perform their assigned tasks?

  1. Availability
    2. Redundancy
    3. Least privilege
    4. Non-repudiation

Correct Answer: 3

Explanation:

Least privilege means users, applications, and services should have only the permissions required to perform their legitimate functions. This reduces the potential impact of mistakes, malware, or stolen credentials. For example, a normal office user generally should not have local administrator rights merely for convenience. Availability focuses on keeping systems accessible, redundancy helps reduce single points of failure, and non-repudiation provides evidence that actions or communications cannot reasonably be denied. Least privilege should be combined with role-based access, regular permission reviews, and controlled elevation when administrative privileges are temporarily required.

Question 176.

A user leaves a laptop unattended in a public conference room. Which control best protects the active session from casual unauthorized access?

  1. Disk Cleanup
    2. File History
    3. Screen resolution settings
    4. Automatic screen lock

Correct Answer: 4

Explanation:

An automatic screen lock protects an unattended active session by requiring authentication before the desktop can be used again. This helps prevent nearby individuals from accessing email, documents, internal applications, or other sensitive information when the user walks away. Disk Cleanup removes unnecessary files, File History protects copies of user data, and screen resolution settings affect display output. Users should also be trained to lock their screen manually before leaving a device unattended. An automatic timeout provides an additional safeguard in case they forget, but the timeout should balance security requirements with practical usability.

Question 177.

Which physical security control is designed primarily to deter theft of a laptop from a desk or workstation area?

  1. Cable lock
    2. Privacy filter
    3. Smart card
    4. Biometric scanner

Correct Answer: 1

Explanation:

A cable lock attaches a portable device to a fixed object and can help deter opportunistic theft. It is not impossible to defeat, but it adds a physical barrier that can make quick removal more difficult. A privacy filter reduces the viewing angle of the display and protects against shoulder surfing. Smart cards and biometric scanners are authentication controls rather than anti-theft devices. Portable computers are especially vulnerable in open offices, classrooms, public areas, and shared workspaces, so physical protection should complement encryption, screen locking, device tracking, and organizational inventory procedures.

Question 178.

Which physical security device is most appropriate for reducing the risk of shoulder surfing in an airport or other public environment?

  1. Mantrap
    2. Privacy filter
    3. Cable lock only
    4. Door alarm

Correct Answer: 2

Explanation:

A privacy filter limits the viewing angle of a screen so information is difficult to read from the side. This is useful in airports, aircraft, coffee shops, public transportation, and open offices where someone nearby could otherwise observe confidential information. A mantrap controls entry to a secure facility, a cable lock reduces theft risk, and a door alarm detects certain physical access events. Privacy filters work best when combined with careful screen positioning, awareness of nearby people, screen locking, and avoiding sensitive work in locations where confidentiality cannot be reasonably maintained.

Question 179.

A technician discovers malware on a user’s workstation that may be communicating with external systems. Which action should be taken early in the response process?

  1. Continue normal network use
    2. Share the suspicious executable with coworkers
    3. Isolate the workstation from the network
    4. Disable all security tools

Correct Answer: 3

Explanation:

Isolating the workstation helps contain the incident by reducing the chance that malware spreads internally, accesses shared resources, or communicates with command-and-control infrastructure. Once isolated, the technician can follow the organization’s incident-response or malware-removal process, identify symptoms, update tools as appropriate, perform scans, remediate the threat, patch vulnerabilities, and verify functionality. Continuing normal network use increases risk. Sharing the suspicious executable can spread the infection, while disabling security tools removes protective controls. Containment is therefore an important early step when malware may be active and network-connected.

Question 180.

After malware has been removed from a workstation, patches have been applied, and full system functionality has been verified, what should the technician do next?

  1. Remove all endpoint protection
    2. Disable the user’s account permanently
    3. Delete all diagnostic information
    4. Document the findings, remediation steps, results, and preventive actions

Correct Answer: 4

Explanation:

Documentation is the final step in the standard troubleshooting methodology after the solution has been implemented and system functionality has been verified. For a malware incident, the record should include the original symptoms, how the threat was identified, containment actions, scanning and remediation steps, patches or configuration changes, verification results, and recommendations for preventing recurrence. Good documentation supports future troubleshooting, trend analysis, security investigations, and organizational learning. Removing endpoint protection or deleting diagnostic information would weaken the environment and eliminate useful evidence. A complete support record helps ensure that the incident is closed in a controlled and professional manner.