{"id":23660,"date":"2026-09-28T08:14:26","date_gmt":"2026-09-28T08:14:26","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23660"},"modified":"2026-09-28T08:14:26","modified_gmt":"2026-09-28T08:14:26","slug":"comptia-a-220-1102-practice-test-questions-and-exam-dumps-part8-q141-160","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/comptia-a-220-1102-practice-test-questions-and-exam-dumps-part8-q141-160\/","title":{"rendered":"CompTIA A+ 220-1102 Practice Test Questions and Exam Dumps Part8 Q141-160"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/220-1102-exam-dumps\"><b>CompTIA A+ 220-1102 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/h2>\n<p>&nbsp;<\/p>\n<p><b>Question 141.<\/b><\/p>\n<p><b>A Windows workstation is joined to a company domain. A technician wants to determine which domain policies are currently affecting the user account. Which command is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> gpresult<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> chkdsk<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> net use<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> taskkill<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">gpresult<\/span><span style=\"font-weight: 400;\"> command displays information about Group Policy settings that have been applied to the computer and user. This makes it useful when a technician needs to verify whether expected security, desktop, software, or network policies are actually taking effect. Depending on the switches used, <\/span><span style=\"font-weight: 400;\">gpresult<\/span><span style=\"font-weight: 400;\"> can provide more detailed information about the Resultant Set of Policy. <\/span><span style=\"font-weight: 400;\">chkdsk<\/span><span style=\"font-weight: 400;\"> checks disks and file-system integrity, <\/span><span style=\"font-weight: 400;\">net use<\/span><span style=\"font-weight: 400;\"> manages connections to network shares, and <\/span><span style=\"font-weight: 400;\">taskkill<\/span><span style=\"font-weight: 400;\"> terminates processes. In a domain environment, confirming effective Group Policy is an important troubleshooting step before assuming that a local Windows setting is the cause of the problem.<\/span><\/p>\n<p><b>Question 142.<\/b><\/p>\n<p><b>A technician has just changed a Group Policy setting and wants the workstation to process the new policy immediately. Which command should be used?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> sfc \/scannow<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> gpupdate<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> hostname<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> arp -a<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">gpupdate<\/span><span style=\"font-weight: 400;\"> command refreshes applicable Group Policy settings for the user and computer. It is often used after a policy has been changed so the administrator does not need to wait for the normal background policy refresh interval. The command can be especially useful during troubleshooting when the technician wants to determine whether a newly configured policy resolves the issue. <\/span><span style=\"font-weight: 400;\">sfc \/scannow<\/span><span style=\"font-weight: 400;\"> checks protected Windows system files, <\/span><span style=\"font-weight: 400;\">hostname<\/span><span style=\"font-weight: 400;\"> displays the local computer name, and <\/span><span style=\"font-weight: 400;\">arp -a<\/span><span style=\"font-weight: 400;\"> shows IP-to-MAC mappings in the local ARP cache. <\/span><span style=\"font-weight: 400;\">gpupdate<\/span><span style=\"font-weight: 400;\"> is specifically intended to refresh Group Policy processing.<\/span><\/p>\n<p><b>Question 143.<\/b><\/p>\n<p><b>A Windows user receives an \u201cAccess Denied\u201d message when attempting to open a folder. The user should have access based on job responsibilities. Which item should the technician examine first?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Screen resolution<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Power plan<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> File and folder permissions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DNS suffix<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An \u201cAccess Denied\u201d message when opening a local or shared folder strongly suggests a permissions issue. The technician should review the user&#8217;s effective file and folder permissions, group memberships, inherited permissions, and any explicit deny settings that could affect access. The goal is to confirm that the user has the minimum rights needed without granting unnecessary administrative permissions. Screen resolution and power settings are unrelated to file access, and a DNS suffix affects name resolution rather than authorization. Permission troubleshooting should also consider whether both share permissions and NTFS permissions apply to the resource, because the most restrictive effective access can limit the user.<\/span><\/p>\n<p><b>Question 144.<\/b><\/p>\n<p><b>Which Windows permission generally gives a user the ability to read, modify, create, and delete files while not necessarily allowing permission changes or ownership changes?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Read<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Read &amp; Execute<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Full Control<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Modify<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Modify permission generally allows a user to read, create, change, and delete files and folders without granting all of the administrative capabilities associated with Full Control. Full Control also includes the ability to change permissions and take ownership, making it more powerful than necessary for many users. Read and Read &amp; Execute provide much more limited access. The principle of least privilege suggests that technicians should grant Modify only when users need to actively work with files. Effective permissions may come from multiple group memberships, so the technician should review combined access rather than looking only at one permission entry.<\/span><\/p>\n<p><b>Question 145.<\/b><\/p>\n<p><b>A user needs to work with files in a shared department folder but should not be able to alter folder permissions. Which permission is generally more appropriate than Full Control?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Modify<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Take Ownership<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Change Permissions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Full Control<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Modify is generally more appropriate when users need to create, edit, and delete files but do not need administrative control over the folder itself. Granting Full Control would also allow the user to change permissions and potentially take ownership, which may violate least-privilege requirements. Take Ownership and Change Permissions are administrative capabilities rather than ordinary working permissions. Security is easier to manage when access is assigned through groups instead of individual accounts. Technicians should also review inherited permissions and share-level permissions when a folder is accessed across the network, since effective access can depend on both layers.<\/span><\/p>\n<p><b>Question 146.<\/b><\/p>\n<p><b>Which Windows feature should a technician use to encrypt an entire laptop drive so that data remains protected if the laptop is stolen?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> File History<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> BitLocker<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Windows Defender Firewall<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> System Restore<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BitLocker provides full-volume encryption and is designed to protect data stored on a drive from unauthorized offline access. It is particularly useful for laptops because a stolen device may otherwise expose the contents of the storage drive even if the Windows password is not known. BitLocker can work with TPM hardware and may require additional startup authentication depending on policy. File History protects versions of user files, Windows Defender Firewall controls network traffic, and System Restore rolls back selected system changes. Recovery keys should be stored securely because they may be required if the normal unlocking process fails.<\/span><\/p>\n<p><b>Question 147.<\/b><\/p>\n<p><b>Which Windows technology provides file-level encryption on an NTFS volume instead of encrypting the entire drive?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BitLocker<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Secure Boot<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Encrypting File System<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Windows Sandbox<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Encrypting File System, or EFS, can encrypt individual files and folders stored on supported NTFS volumes. This differs from BitLocker, which encrypts an entire volume. EFS can be useful when only selected data needs file-level confidentiality, but proper certificate and key management is critical. If the required encryption certificate and private key are lost and no recovery mechanism exists, legitimate users may lose access to the data. Secure Boot protects the startup process, and Windows Sandbox provides an isolated temporary operating environment. EFS is specifically intended for selective file and folder encryption.<\/span><\/p>\n<p><b>Question 148.<\/b><\/p>\n<p><b>A technician is preparing to encrypt a laptop with BitLocker. Which item should be securely backed up before the deployment is considered complete?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Desktop wallpaper<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Browser history<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Temporary files<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> BitLocker recovery key<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The BitLocker recovery key should be securely backed up because it may be required if the normal unlocking method fails. Situations such as TPM changes, firmware updates, hardware replacement, or certain startup security events can trigger a recovery prompt. Without the recovery key, authorized access to the encrypted data may be difficult or impossible. The key should be stored according to organizational policy in a secure location that is separate from the protected device. Browser history, temporary files, and wallpaper are not critical encryption-recovery information. Key management is a fundamental part of any encryption deployment.<\/span><\/p>\n<p><b>Question 149.<\/b><\/p>\n<p><b>Which Windows security feature helps prevent untrusted bootloaders from running before the operating system starts?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Secure Boot<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> File History<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Screen saver<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Disk Cleanup<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Boot is a UEFI feature that validates digital signatures of boot components before allowing them to execute. This helps reduce the risk of bootkits and other malicious software that attempts to compromise a system before Windows security controls become active. Secure Boot is part of a broader trusted-startup architecture and complements technologies such as TPM and BitLocker. File History protects user files, a screen saver does not validate boot software, and Disk Cleanup removes temporary or unnecessary data. Secure Boot primarily protects the integrity of the startup process.<\/span><\/p>\n<p><b>Question 150.<\/b><\/p>\n<p><b>A technician needs to test an unknown but potentially unsafe application without permanently changing the host Windows installation. Which feature is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> System Restore<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Windows Sandbox<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disk Management<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> File History<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Windows Sandbox provides a temporary, isolated Windows environment where software can be executed separately from the main operating system. When the sandbox is closed, the temporary environment and changes made inside it are discarded. This makes it useful for testing unknown applications or examining software that is not yet trusted. It does not replace a dedicated malware-analysis environment for highly dangerous samples, but it provides practical isolation for many support scenarios. System Restore rolls back certain system changes, Disk Management handles storage, and File History maintains versions of user data.<\/span><\/p>\n<p><b>Question 151.<\/b><\/p>\n<p><b>A company wants to prevent users from installing software unless it has been approved by IT. Which combination of controls is most appropriate?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Give all users administrator rights and rely on policy reminders<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Disable passwords to simplify support<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Use standard user accounts and application-control policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Share one administrator account among employees<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Standard user accounts combined with application-control policies provide stronger protection against unauthorized software installation. Standard users have fewer privileges than administrators, reducing the ability of untrusted applications to make system-wide changes. Application-control technologies can further restrict which programs are allowed to run. Giving everyone administrator rights would increase malware and configuration risk. Shared administrator accounts weaken accountability, and disabling passwords is obviously insecure. Least privilege works best when combined with centralized software deployment, patch management, endpoint protection, and clear processes for requesting approved applications.<\/span><\/p>\n<p><b>Question 152.<\/b><\/p>\n<p><b>Which authentication method uses two different factor categories, such as a password and a fingerprint?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Single sign-on<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Password history<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Account lockout<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Multifactor authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication requires authentication factors from two or more different categories. A password represents something the user knows, while a fingerprint represents something the user is. Because these factors are independent, compromising one does not automatically compromise the entire authentication process. Single sign-on allows one authentication event to provide access to multiple systems but does not necessarily use multiple factors. Password history prevents recent password reuse, while account lockout limits repeated failed attempts. MFA is one of the strongest practical ways to reduce the impact of stolen or guessed passwords.<\/span><\/p>\n<p><b>Question 153.<\/b><\/p>\n<p><b>Which authentication factor category is represented by a hardware security token?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Something you have<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Something you know<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Something you are<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Somewhere you are<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hardware security token represents \u201csomething you have.\u201d Other possession factors include smart cards and certain mobile authentication devices. \u201cSomething you know\u201d includes passwords and PINs, while \u201csomething you are\u201d includes biometrics such as fingerprints or facial characteristics. Location can sometimes be used as contextual information but is a different category. Strong MFA implementations combine distinct factor types, such as a password and a hardware token. Technicians should not count two passwords as two separate factors because both belong to the same knowledge category.<\/span><\/p>\n<p><b>Question 154.<\/b><\/p>\n<p><b>Which authentication factor category is represented by a PIN?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Something you are<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Something you know<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Something you have<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Somewhere you are<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A PIN is a knowledge factor, or \u201csomething you know,\u201d because authentication depends on information memorized by the user. Passwords and answers to security questions are other knowledge factors. Biometric characteristics such as fingerprints represent \u201csomething you are,\u201d while physical tokens and smart cards represent \u201csomething you have.\u201d A strong multifactor design combines different categories rather than merely using multiple credentials from the same category. Although a PIN may be shorter than a password, its security characteristics can differ depending on where and how it is used, such as when tied to a specific protected device.<\/span><\/p>\n<p><b>Question 155.<\/b><\/p>\n<p><b>Which security policy is intended to stop users from cycling rapidly through passwords and returning to a recently used password?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Account lockout duration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Screen lock timeout<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Password history<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> File retention<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Password history prevents users from immediately reusing one of a specified number of previous passwords. This is useful when an organization enforces password changes and wants to discourage users from simply cycling through a few familiar passwords. Account lockout controls repeated failed authentication attempts, screen lock timeout protects unattended sessions, and file retention determines how long data is kept. Password history is most effective when combined with appropriate password length, MFA, secure reset procedures, and monitoring rather than being relied upon as the only password-security mechanism.<\/span><\/p>\n<p><b>Question 156.<\/b><\/p>\n<p><b>Which security control automatically locks or disables an account after a configured number of failed login attempts?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Password history<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> File permissions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> BitLocker<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Account lockout policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An account lockout policy limits repeated password-guessing attempts by temporarily locking an account after a specified number of failed authentication attempts. This can slow brute-force attacks, although organizations must configure the threshold carefully to avoid making denial-of-service attacks too easy. Password history prevents password reuse, file permissions control resource access, and BitLocker encrypts storage. Account lockout should be combined with MFA, secure password practices, monitoring, and alerts for suspicious authentication patterns. Technicians should also understand how users regain access when lockouts occur.<\/span><\/p>\n<p><b>Question 157.<\/b><\/p>\n<p><b>A user receives an email containing an urgent message that appears to come from the company&#8217;s finance department and asks the user to enter credentials on a linked website. Which attack is being attempted?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Phishing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Tailgating<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Shoulder surfing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Dumpster diving<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Phishing uses deceptive electronic messages to trick recipients into revealing credentials, opening malicious attachments, or visiting fraudulent websites. Attackers often create urgency, impersonate trusted departments, or use realistic branding to increase credibility. Tailgating is a physical access technique, shoulder surfing involves observing sensitive information, and dumpster diving involves searching discarded materials. Users should verify unexpected requests through trusted channels, avoid clicking suspicious links, and report phishing attempts. Email security controls can help, but user awareness remains important because sophisticated phishing messages may bypass technical filtering.<\/span><\/p>\n<p><b>Question 158.<\/b><\/p>\n<p><b>Which social-engineering attack specifically targets executives or other high-value individuals with carefully crafted fraudulent messages?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Smishing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Whaling<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Tailgating<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Shoulder surfing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Whaling is a targeted form of phishing aimed at executives, senior managers, or other high-value individuals who may have access to sensitive information or authority over financial transactions. Attackers often research their targets and create convincing messages involving legal requests, invoices, confidential documents, or urgent executive decisions. Smishing uses text messages, tailgating is a physical access technique, and shoulder surfing involves observing information visually. Organizations should require independent verification for high-risk financial and administrative requests because whaling attacks often rely on urgency and authority to bypass normal procedures.<\/span><\/p>\n<p><b>Question 159.<\/b><\/p>\n<p><b>A user receives a text message claiming a package cannot be delivered until the user signs in through a provided link. Which type of attack is this?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Vishing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Whaling<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Smishing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Tailgating<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Smishing is phishing conducted through SMS or similar text messaging services. Attackers frequently impersonate delivery companies, financial institutions, government agencies, or employers and try to create urgency so the victim clicks a malicious link. The linked page may attempt to steal credentials, payment information, or install malware. Vishing uses voice communication, whaling targets high-value individuals, and tailgating is a physical security attack. Users should avoid clicking unexpected text-message links and instead verify notifications through official applications or independently accessed websites.<\/span><\/p>\n<p><b>Question 160.<\/b><\/p>\n<p><b>A technician successfully resolves a malware incident, verifies the workstation is functioning properly, and confirms that updates and endpoint protection are current. What is the final troubleshooting step?<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disable automatic updates<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove the user&#8217;s password<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Clear all event logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Document findings, actions, results, and preventive recommendations<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Documentation is the final step after the technician has verified full system functionality and confirmed that the original problem is resolved. The support record should describe the reported symptoms, troubleshooting process, identified cause, remediation steps, updates or configuration changes, verification results, and any recommendations intended to reduce recurrence. For a malware incident, documentation can also support security trend analysis and future incident response. Disabling updates or removing authentication would weaken security, while clearing logs could destroy useful diagnostic or investigative information. Good documentation improves accountability, knowledge sharing, and the efficiency of future troubleshooting.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full CompTIA A+ 220-1102 Exam Dumps and Practice Test Dumps &nbsp; Question 141. A Windows workstation is joined to a company domain. A technician wants to determine which domain policies are currently affecting the user account. Which command is most appropriate? gpresult 2. chkdsk 3. net use 4. taskkill Correct Answer: 1 Explanation: The [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23660"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23660"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23660\/revisions"}],"predecessor-version":[{"id":23661,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23660\/revisions\/23661"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23660"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23660"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23660"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}