CertSafari

    Free CompTIA A+ Core 2 Sample Questions

    35 free sample questions from our bank of 352+, covering every exam domain, with answers and detailed explanations. Updated October 2026.

    Domain 1: Operating Systems

    Subdomain 1.1: Explain common operating system (OS) types and their purposes.

    1.A school wants inexpensive student laptops that boot in seconds, update themselves in the background, and are managed centrally from a cloud admin console. Students will mostly use web apps and Google Workspace. Which operating system best fits?

    1. A.ChromeOS
    2. B.Windows 11 Pro
    3. C.macOS
    4. D.Ubuntu Desktop
    Show answer & explanation

    Correct answer: A — ChromeOS

    • A. ChromeOS is correct because it is built around the Chrome browser and web apps, boots quickly, updates automatically, and is managed through the Google Admin console on low-cost hardware.
    • B. Windows 11 Pro is incorrect because it needs heavier hardware, is managed through tools such as Intune or Group Policy, and updates on a slower, less seamless schedule.
    • C. macOS is incorrect because it runs only on more expensive Apple hardware, which does not fit an inexpensive classroom laptop budget.
    • D. Ubuntu Desktop is incorrect because it is a general-purpose Linux distribution without built-in cloud-console management or automatic background updates for a fleet.

    Subdomain 1.3: Compare and contrast basic features of Microsoft Windows editions.

    2.A small company asks you to bring a user's laptop running Windows 11 Home into its Active Directory domain so that Group Policy applies. What should you do?

    1. A.Rename the workgroup to match the domain name so the laptop receives policy from the domain controller
    2. B.Upgrade the laptop to Windows 11 Pro with a valid Pro product key, because Pro adds domain join support
    3. C.Reinstall using Windows 11 Home N media, which adds the domain client that standard Home images leave out
    4. D.Enable the Domain Services optional feature under Windows Features, then join the domain from System Properties
    Show answer & explanation

    Correct answer: B — Upgrade the laptop to Windows 11 Pro with a valid Pro product key, because Pro adds domain join support

    • A. Incorrect. A workgroup name is only a label for peer-to-peer grouping; matching the domain name does not authenticate the PC or deliver Group Policy.
    • B. Correct. Windows 11 Home cannot join an Active Directory domain, and an edition upgrade to Pro (or higher) enables domain join and Group Policy processing.
    • C. Incorrect. N editions only remove media features such as Windows Media Player and do not add or change networking or domain capabilities.
    • D. Incorrect. No optional feature turns Home into a domain member; the limitation is built into the edition itself, so System Properties cannot complete a domain join.

    Subdomain 1.4: Given a scenario, use Microsoft Windows operating system features and tools.

    3.Users report that a workstation's disk is constantly busy and the system stutters. A technician needs to see which individual files and processes are generating the most disk reads and writes in real time. Which tool is best suited?

    1. A.resmon.exe
    2. B.msconfig.exe
    3. C.dfrgui.exe
    4. D.taskschd.msc
    Show answer & explanation

    Correct answer: A — resmon.exe

    • A. Correct. Resource Monitor (resmon.exe) breaks down CPU, memory, disk, and network activity per process and lists the files each process is reading or writing.
    • B. Incorrect. System Configuration (msconfig.exe) controls boot options and startup selections and does not monitor live disk activity.
    • C. Incorrect. Defragment and Optimize Drives (dfrgui.exe) analyzes and optimizes fragmentation or trims SSDs, but it cannot identify which process is causing disk activity.
    • D. Incorrect. Task Scheduler (taskschd.msc) creates and manages scheduled tasks and does not report per-process disk usage.

    Subdomain 1.5: Given a scenario, use the appropriate Microsoft command-line tools.

    4.An administrator must copy a 2 TB share to a new server, keeping NTFS permissions and timestamps. The job will be rerun nightly so that only changed files are copied and files deleted from the source are removed from the destination. Which command fits?

    1. A.`xcopy D:\Data E:\Data /E` to copy subfolders, including empty ones, and purge files that were removed from the source
    2. B.`copy D:\Data E:\Data /Y` to overwrite existing files silently and carry the source ACLs across on every run
    3. C.`net use E: \\NEWSRV\Data` to map the target share so Windows synchronizes changed files between both locations
    4. D.`robocopy D:\Data E:\Data /MIR /COPYALL` to mirror the tree, copy security data, and skip unchanged files
    Show answer & explanation

    Correct answer: D — `robocopy D:\Data E:\Data /MIR /COPYALL` to mirror the tree, copy security data, and skip unchanged files

    • A. `xcopy /E` copies subfolders but never deletes destination files that disappeared from the source, and it does not retain all NTFS security data by default.
    • B. `copy` does not recurse into subfolders and does not mirror deletions, so it cannot keep two directory trees in step.
    • C. `net use` only maps a drive letter to a share; it does not move or synchronize any files.
    • D. `robocopy` with `/MIR` mirrors the directory tree, deleting extra destination files and skipping unchanged ones, while `/COPYALL` preserves data, attributes, timestamps, and security information.

    Subdomain 1.10: Given a scenario, install applications according to requirements.

    5.A company is opening a training room with 30 identical PCs. Each needs the same operating system, the same 12 applications, and the same settings, and everything must be ready within one day. Which distribution method fits best?

    1. A.Build one reference PC, capture a system image of it, and deploy that image to each of the other PCs over the network
    2. B.Visit each PC with a USB drive and install the operating system and each of the 12 applications manually from downloaded packages
    3. C.Email every trainer the vendor download links for the 12 applications and have them install the software when they log in
    4. D.Mount the application ISO files on each PC in turn and run each setup wizard separately while keeping a checklist of options
    Show answer & explanation

    Correct answer: A — Build one reference PC, capture a system image of it, and deploy that image to each of the other PCs over the network

    • A. Correct. Image deployment captures a fully configured reference system once and applies it to many machines. That gives identical results and fits the one-day deadline.
    • B. Manual installs from a USB drive repeat the same work 30 times and invite inconsistent settings between machines. It cannot meet the deadline well.
    • C. Self-service installs by trainers produce inconsistent versions and options, and standard users may lack the rights to install software. It also delays readiness.
    • D. Mounting ISOs on each PC is still a per-machine, per-application process. It is repeatable but slow and error prone at this scale.

    Subdomain 1.11: Given a scenario, install and configure cloud-based productivity tools.

    6.Administrators enable ______ so that users sign in once with a single set of credentials and then reach email, storage and chat without being prompted again.

    1. A.Known Folder Move
    2. B.Files On-Demand
    3. C.single sign-on (SSO)
    Show answer & explanation

    Correct answer: C — single sign-on (SSO)

    • A. Incorrect. Known Folder Move redirects Desktop, Documents and Pictures into OneDrive and has nothing to do with authentication.
    • B. Incorrect. Files On-Demand controls whether synced files are stored locally or only online, not how users sign in.
    • C. Correct. Single sign-on lets one authentication cover multiple cloud services without repeated credential prompts.

    Subdomain 1.2: Given a scenario, perform OS installations and upgrades in a diverse environment.

    7.Which description best matches zero-touch deployment of a new Windows laptop?

    1. A.A technician boots the laptop from a USB drive and answers each setup prompt by hand, then installs the standard applications
    2. B.A technician connects the laptop to a deployment share and selects a task sequence from a menu at each build step
    3. C.The user starts setup from the recovery partition and follows the prompts to return the laptop to its factory configuration
    4. D.The device is pre-registered with the organization and configures itself automatically on its first online start-up
    Show answer & explanation

    Correct answer: D — The device is pre-registered with the organization and configures itself automatically on its first online start-up

    • A. Incorrect. Booting from USB and answering each prompt by hand is a manual, hands-on installation, which is the opposite of zero touch.
    • B. Incorrect. Selecting a task sequence at each build step requires a technician to attend the device, so it remains a hands-on deployment.
    • C. Incorrect. Using the recovery partition resets the device to factory state and needs user interaction, so it is not a zero-touch process.
    • D. Correct. In zero-touch deployment (for example Windows Autopilot), the device is pre-registered and configures itself during first start-up without IT handling it.

    Subdomain 1.6: Given a scenario, configure Microsoft Windows settings.

    8.An employee stores project documents on a secondary drive at D:\Projects, and searching from the Start menu never returns files from it. Which Control Panel tool should the technician use to fix this?

    1. A.Devices and Printers, to add the secondary drive as a recognized storage device
    2. B.Programs and Features, to repair the Windows Search component from the installed list
    3. C.Indexing Options, to add D:\Projects to the included locations in the index
    4. D.System, to extend the page file onto the secondary drive for search caching
    Show answer & explanation

    Correct answer: C — Indexing Options, to add D:\Projects to the included locations in the index

    • A. Incorrect. Devices and Printers lists hardware such as printers and peripherals and does not control which folders Windows Search covers.
    • B. Incorrect. Programs and Features handles installed applications and optional features, and a location that was never indexed is not a damaged component to repair.
    • C. Correct. Indexing Options defines the locations Windows Search scans, so adding the folder lets the search index return its files.
    • D. Incorrect. The page file supplies virtual memory and has nothing to do with which folders are scanned by Windows Search.

    Subdomain 1.7: Given a scenario, configure Microsoft Windows networking features on a client/desktop.

    9.A desktop with the static address 192.168.10.45 and mask 255.255.255.0 can ping other hosts on 192.168.10.0/24 but cannot reach anything on other subnets or the internet. Which setting should the technician check first?

    1. A.The default gateway, which must be a router address inside 192.168.10.0/24 for traffic to leave the local subnet
    2. B.The alternate DNS server, which must be on the same subnet before packets can be forwarded to remote networks
    3. C.The WINS server entry, which must point at the router before Windows can send any traffic to a remote subnet
    4. D.The adapter's MAC address filter, which must list the router before frames for remote destinations are transmitted
    Show answer & explanation

    Correct answer: A — The default gateway, which must be a router address inside 192.168.10.0/24 for traffic to leave the local subnet

    • A. Correct. Local pings work, so the address and mask are fine. Traffic for other subnets goes to the default gateway; if it is missing or wrong, only the local subnet is reachable.
    • B. Incorrect. DNS servers resolve names and need not be on the local subnet. A bad DNS entry would not block pings to remote IP addresses.
    • C. Incorrect. WINS is a legacy name-resolution service and has no role in routing packets to remote subnets.
    • D. Incorrect. Windows does not use a MAC filter list to decide where remote traffic goes; routing depends on the gateway, not on a frame allow list.

    Subdomain 1.8: Explain common features and tools of the macOS/desktop operating system.

    10.A user downloads `Slack.dmg` from the vendor's website and asks how to install the application on their Mac. Which procedure is correct?

    1. A.Run the file from Terminal after marking it executable with `chmod +x`, because a disk image is a shell script that installs itself
    2. B.Open the disk image to mount it, drag the app bundle into the /Applications folder, then eject the mounted volume when finished
    3. C.Extract the contents into /System/Library with Disk Utility, because applications must live in the protected system folder to launch
    4. D.Double-click the file to start a setup wizard that writes a registry entry registering the application with the operating system
    Show answer & explanation

    Correct answer: B — Open the disk image to mount it, drag the app bundle into the /Applications folder, then eject the mounted volume when finished

    • A. A .dmg is a mounted disk image, not a shell script, so marking it executable and running it from Terminal does not install anything. Installation is normally a drag-and-drop copy.
    • B. A .dmg mounts as a virtual volume containing an .app bundle. Dragging the bundle to /Applications copies it into place, and ejecting the volume afterward cleans up the installer.
    • C. /System/Library is owned by the operating system and protected by System Integrity Protection, so third-party apps are not placed there. Disk Utility does not extract installers into it either.
    • D. macOS has no registry; that is a Windows concept. A .dmg does not launch a setup wizard, and apps need no registration beyond being copied to /Applications.

    Subdomain 1.9: Identify common features and tools of the Linux client/desktop operating system.

    11.A help desk technician must run one package update with administrative rights on a shared Ubuntu workstation. The company wants every privileged action tied to the individual's own account in the logs. What should the technician do?

    1. A.Prefix the update command with sudo and authenticate with their own password so activity is logged by user
    2. B.Run su - and enter the root password, then stay in the root shell for the rest of the work session
    3. C.Edit /etc/shadow to copy the root password hash onto their own account so every command runs elevated
    4. D.Log in directly as root at the display manager and share the root password with the whole support team
    Show answer & explanation

    Correct answer: A — Prefix the update command with sudo and authenticate with their own password so activity is logged by user

    • A. Correct. sudo elevates a single command using the user's own credentials and records the invoking account, giving individual accountability.
    • B. Incorrect. su - opens a full root shell with the shared root password, so later actions are attributed to root rather than the person.
    • C. Incorrect. Copying a hash in /etc/shadow is an unsafe hack that duplicates credentials and defeats per-user accountability.
    • D. Incorrect. Logging in as root with a shared password removes individual attribution and violates the principle of least privilege.

    Domain 2: Security

    Subdomain 2.1: Summarize various security measures and their purposes.

    12.A new help desk technician must reset user passwords for the Sales organizational unit only. Which approach best follows the principle of least privilege?

    1. A.Add the technician to the Domain Admins group temporarily and remove the membership after the first week
    2. B.Give the technician the shared administrator credentials from the team vault for use during password resets
    3. C.Place the technician in the Power Users group on every workstation so resets can be performed locally
    4. D.Delegate only the password reset permission on the Sales OU to the technician's own account
    Show answer & explanation

    Correct answer: D — Delegate only the password reset permission on the Sales OU to the technician's own account

    • A. Domain Admins grants far more rights than password resets require, and even a temporary membership exposes the whole domain to misuse.
    • B. A shared administrator account gives unlimited rights, destroys individual accountability in audit logs, and exceeds what the task needs.
    • C. Power Users is a legacy local group that does not control domain password resets, and it grants unneeded rights on every workstation.
    • D. Delegating just the reset-password permission on one OU gives the technician exactly the access the job requires and nothing more, which is the definition of least privilege.

    Subdomain 2.2: Given a scenario, configure and apply basic Microsoft Windows OS security settings.

    13.A user connects to a shared folder over the network. The share permission for the user's group is Read, while the NTFS permission on the same folder for that group is Modify. What is the user's effective access when working through the share?

    1. A.Modify, because the NTFS permission is evaluated first and the less restrictive entry overrides the share-level setting.
    2. B.Full Control, because the share and NTFS entries are added together and the combined total is then rounded up.
    3. C.Read, because over the network the most restrictive result of the share and NTFS permissions is what applies.
    4. D.No access, because conflicting share and NTFS entries cancel each other out and leave the folder without an allow.
    Show answer & explanation

    Correct answer: C — Read, because over the network the most restrictive result of the share and NTFS permissions is what applies.

    • A. NTFS does not override a more restrictive share permission for network access. Modify would only apply to a user signed in locally at the file server.
    • B. Share and NTFS permissions are never added into a higher level of access, and nothing is rounded up. The two sets are compared and the stricter one wins.
    • C. Correct. When both layers apply, the effective permission for network users is the most restrictive of the two, so Read at the share caps the Modify granted by NTFS.
    • D. Allow entries at different layers do not cancel each other out. The user simply receives the more restrictive of the two allowed permissions, not an empty result.

    Subdomain 2.3: Compare and contrast wireless security protocols and authentication methods.

    14.A user on a domain-joined workstation suddenly cannot access file shares. Event logs show Kerberos errors about a clock skew, and the workstation's time is 12 minutes ahead of the domain controller. What is the cause?

    1. A.The TACACS+ server stopped accepting the workstation's password because the packet body was no longer encrypted
    2. B.The WPA2 group key rotated during the session and the workstation cannot decrypt broadcast frames until reboot
    3. C.Kerberos rejects ticket timestamps when the client and KDC clocks differ by more than about five minutes
    4. D.The RADIUS shared secret on the workstation expired and the access point stopped forwarding authentication requests
    Show answer & explanation

    Correct answer: C — Kerberos rejects ticket timestamps when the client and KDC clocks differ by more than about five minutes

    • A. Incorrect. TACACS+ governs device administration and is not involved in file share access. Its encryption is not time-based and does not generate Kerberos skew errors.
    • B. Incorrect. Group key rotation affects wireless broadcast traffic, not Kerberos validation. The clock-skew error points specifically to time disagreement between client and domain controller.
    • C. Correct. Kerberos tickets and authenticators carry timestamps to prevent replay, so a clock outside the default five-minute tolerance causes the KDC or service to reject them. Syncing time fixes it.
    • D. Incorrect. RADIUS shared secrets are used between an access point or switch and the RADIUS server. They are not part of Kerberos domain logons and would not log clock-skew errors.

    Subdomain 2.4: Summarize types of malware and tools/methods for detection, removal, and prevention.

    15.A technician finds that a workstation keeps redirecting browsers to unfamiliar sites. Updated antivirus scans report clean, yet an offline check shows hidden drivers that survive every removal attempt. What is the most reliable way to restore the machine to a trusted state?

    1. A.End the unfamiliar processes in Task Manager, clear the browser cache, and delete the temporary internet files folder
    2. B.Turn the software firewall off and on again so the hidden drivers are reset to their default, unloaded state
    3. C.Back up the user's documents, then wipe the drive and reinstall the operating system from trusted installation media
    4. D.Update the antivirus signatures again, run another full scan from within the installed OS, and reboot normally afterward
    Show answer & explanation

    Correct answer: C — Back up the user's documents, then wipe the drive and reinstall the operating system from trusted installation media

    • A. Incorrect. Ending processes and clearing the cache only touches visible user-level items; the hidden drivers reload at the next boot.
    • B. Incorrect. Toggling the software firewall only changes network filtering rules and does not unload or remove kernel-level drivers.
    • C. Correct. A rootkit hides below the level the running OS and its antivirus can inspect, so wiping the drive and reinstalling from trusted media is the dependable remedy.
    • D. Incorrect. A scan run from inside the infected OS relies on the same compromised system calls the rootkit filters, so it keeps reporting clean.

    Subdomain 2.6: Given a scenario, implement procedures for basic small office/home office (SOHO) malware removal.

    16.After the infection is removed and protection is back in place, the technician finishes the SOHO malware removal procedure by educating the end user about ______.

    1. A.safe computing habits, such as spotting phishing emails and avoiding downloads from untrusted websites
    2. B.disabling the software firewall permanently, which stops pop-up prompts that interrupt the user's daily work
    3. C.reimaging the computer monthly from the original factory image to remove any unseen threats from the drive
    4. D.sharing administrator credentials with coworkers so that any of them can quickly reinstall security software
    Show answer & explanation

    Correct answer: A — safe computing habits, such as spotting phishing emails and avoiding downloads from untrusted websites

    • A. User education on phishing, risky downloads and untrusted sites is the final step of the procedure. It targets how most infections begin and lowers the chance of reinfection.
    • B. Disabling the firewall removes a protective control and increases exposure. Security training teaches users to keep protections enabled, not to turn them off to avoid prompts.
    • C. Monthly reimaging is not part of the procedure and is wasteful for a SOHO setting. Reimaging is a response to failed remediation, not an educational topic for routine use.
    • D. Sharing administrator credentials is poor security practice that widens the attack surface. Education stresses least privilege and individual accounts rather than shared admin access.

    Subdomain 2.7: Given a scenario, apply workstation security options and hardening techniques.

    17.A company hires summer interns whose contracts all end on 30 August. The help desk wants their accounts to stop working automatically on that date, without relying on someone remembering to clean them up. What should the technician configure?

    1. A.Set a password expiration of 90 days in the local security policy so each intern must choose a new password in time
    2. B.Restrict each intern's log-in hours to weekdays between 08:00 and 18:00 so that sign-ins fail outside working time
    3. C.Add each intern to the Guests group so that their access is limited and no longer valid after the contract finishes
    4. D.Set an account expiration date of 30 August on each intern's account so it is disabled automatically afterward
    Show answer & explanation

    Correct answer: D — Set an account expiration date of 30 August on each intern's account so it is disabled automatically afterward

    • A. Incorrect. Password expiration only forces a password change, and the intern could still sign in after choosing a new password on 30 August.
    • B. Incorrect. Log-in time restrictions limit when an account can be used each day, but they never end the account's validity on a calendar date.
    • C. Incorrect. Placing users in the Guests group reduces their permissions but does not make the account stop working on any particular date.
    • D. Correct. An account expiration date disables the account itself on a fixed day, which fits temporary staff whose contract end date is known in advance.

    Subdomain 2.8: Given a scenario, apply common methods for securing mobile devices.

    18.A company lets employees read corporate email on personal phones. Security requires a passcode on each phone and wants to remove only company data when an employee leaves. Which approach meets both requirements?

    1. A.Enroll the phones in an MDM service that pushes a passcode profile and supports selective wipe of managed data
    2. B.Hand every departing employee's phone to the help desk for a full factory reset that also erases their personal photos
    3. C.Install a locator application on each phone and let the help desk run a complete remote wipe when someone departs
    4. D.Apply content filtering on the office Wi-Fi so that only approved sites can reach the mail server from personal phones
    Show answer & explanation

    Correct answer: A — Enroll the phones in an MDM service that pushes a passcode profile and supports selective wipe of managed data

    • A. Correct. MDM enforces profile security requirements such as a passcode and can retire a BYOD device by wiping only the corporate-managed data, leaving personal content untouched.
    • B. Incorrect. A full factory reset removes personal data the company does not own and does nothing to enforce a passcode while the employee is still working.
    • C. Incorrect. A locator application can find or fully wipe a device but cannot enforce passcode policy or separate corporate data from personal data.
    • D. Incorrect. Filtering traffic on the office network does not apply off the premises and cannot set a passcode or remove stored company email from a phone.

    Subdomain 2.9: Compare and contrast common data destruction and disposal methods.

    19.A small office has five failed hard drives and no budget for a vendor. A technician plans to destroy them by drilling. Which approach makes drilling effective?

    1. A.Drill a single hole through the drive's outer cover only, since breaking the airtight seal alone erases the magnetic data
    2. B.Drill several holes completely through the housing and every platter so the surfaces cannot be read in a recovery lab
    3. C.Drill out the screws holding the controller circuit board, then discard the board because it stores all of the user data
    4. D.Drill into the label side until the serial number is unreadable, because the serial number is what links to the data
    Show answer & explanation

    Correct answer: B — Drill several holes completely through the housing and every platter so the surfaces cannot be read in a recovery lab

    • A. Breaking the seal does not erase anything because data remains encoded on the platters. A cover-only hole leaves the platters intact and readable.
    • B. Multiple holes through the housing and all platters physically damage the recording surfaces, so data cannot be reconstructed even by a recovery lab. This is how drilling is made effective on a hard drive.
    • C. The circuit board holds the controller, not the user data, which lives on the platters. Discarding the board leaves the platters recoverable by transplanting a compatible board.
    • D. A serial number is not a key to the data. Removing the label does nothing to the information stored on the platters.

    Subdomain 2.10: Given a scenario, apply security settings on SOHO wireless and wired networks.

    20.A home office router still uses WEP, although every laptop and phone in the house supports WPA3. The user asks for the strongest encryption setting the devices can use. What should the technician configure?

    1. A.WEP with a 128-bit key and the SSID hidden from broadcast to make the key harder to find
    2. B.An open network with no encryption and MAC address filtering applied to approved devices
    3. C.WPA3-Personal with AES encryption and a long, randomly generated passphrase
    4. D.WPA2-Personal using TKIP encryption and a short, memorable passphrase for easy entry
    Show answer & explanation

    Correct answer: C — WPA3-Personal with AES encryption and a long, randomly generated passphrase

    • A. Incorrect. WEP is broken and its keys can be recovered in minutes; hiding the SSID does not strengthen the encryption in any way.
    • B. Incorrect. An open network sends traffic unencrypted, and MAC filtering offers no confidentiality because addresses are visible and easy to spoof.
    • C. Correct. WPA3-Personal with AES provides current, strong encryption and resists offline guessing better than earlier modes, especially with a long random passphrase.
    • D. Incorrect. TKIP is deprecated and a short passphrase is easy to guess, so this combination is weaker than WPA3 even though it is better than WEP.

    Subdomain 2.11: Given a scenario, configure relevant security settings in a browser.

    21.Which statement accurately describes the effect of using a private-browsing window?

    1. A.The browser discards local history, cookies and form entries once all private windows close, but network administrators can still see traffic.
    2. B.The browser encrypts all outbound traffic with a built-in tunnel, so employers and internet providers cannot see which sites the user visits.
    3. C.The browser masks the device's public IP address from every visited site, so the sites cannot tell the user's approximate location.
    4. D.The browser blocks all third-party extensions and scripts, so the session is protected from malware delivered by malicious web pages.
    Show answer & explanation

    Correct answer: A — The browser discards local history, cookies and form entries once all private windows close, but network administrators can still see traffic.

    • A. Private mode keeps session data such as history, cookies and form entries only in memory and drops it at the end. It does nothing to hide activity from the network, so proxies and ISPs still see traffic.
    • B. Private browsing does not create a VPN or encrypted tunnel. Employers and internet providers can still observe which sites are visited through the network.
    • C. The public IP address is assigned by the network and remains visible to every site visited. Hiding it requires a VPN or proxy, not private mode.
    • D. Private mode does not block scripts, and extensions can be allowed in it. Malicious pages can still attack the browser, so it offers no malware protection.

    Domain 3: Software Troubleshooting

    Subdomain 3.2: Given a scenario, troubleshoot common mobile OS and application issues.

    22.A user's email app crashes at launch after a recent app update, and the technician has already restarted the phone. Which actions are appropriate next steps? (Select TWO.)(Select 2)

    1. A.Lower the screen resolution to the lowest setting, because the app now requires a smaller framebuffer to render.
    2. B.Disable the phone's cellular modem permanently so the app cannot download any new corrupted configuration data.
    3. C.Force stop the app and clear its cache, then try launching it again to discard corrupted temporary files.
    4. D.Uninstall the app and reinstall the latest version from the official store to replace damaged program files.
    5. E.Turn off the phone's NFC antenna since the app uses it to authenticate each launch with the mail server.
    Show answer & explanation

    Correct answers: C, D — Force stop the app and clear its cache, then try launching it again to discard corrupted temporary files.; Uninstall the app and reinstall the latest version from the official store to replace damaged program files.

    • A. Incorrect. Reducing screen resolution does not address the app crash and would degrade the display for every application.
    • B. Incorrect. Permanently disabling the cellular modem would break calls and data for the whole device and does not repair a corrupted install.
    • C. Correct. Force stopping and clearing the cache removes temporary data that commonly causes crashes after an update, without touching user data.
    • D. Correct. Reinstalling the app from the official store replaces any damaged or partially applied program files left by the update.
    • E. Incorrect. Mail clients authenticate over the network and do not use NFC, so switching it off has no impact on the crash.

    Subdomain 3.3: Given a scenario, troubleshoot common mobile OS and application security issues.

    23.A user receives a data-usage limit notification on the 20th of the month although their habits have not changed. The Settings app shows a recently installed wallpaper app using several GB of background cellular data. What is the most appropriate next step?

    1. A.Force-stop and uninstall the wallpaper app, then run a mobile anti-malware scan and review other recently installed apps
    2. B.Disable Bluetooth and location services, because those radios are the main source of background cellular traffic
    3. C.Clear the browser cache and cookies, which removes the cached data that is counted against the monthly limit
    4. D.Move the user to a higher monthly data plan, since the spike reflects normal growth in streaming, podcasts, and cloud backups
    Show answer & explanation

    Correct answer: A — Force-stop and uninstall the wallpaper app, then run a mobile anti-malware scan and review other recently installed apps

    • A. Correct. Per-app data usage identifies the likely malicious app; removing it and scanning addresses the cause rather than the symptom.
    • B. Incorrect. Bluetooth does not use the cellular data allowance, and location services produce very little traffic compared with several GB.
    • C. Incorrect. Cached browser files are stored locally and are not counted toward the cellular limit; the traffic comes from the app.
    • D. Incorrect. The usage is attributed to one wallpaper app running in the background, so a bigger plan only pays for a probable data leak.

    Subdomain 3.4: Given a scenario, troubleshoot common personal computer (PC) security issues.

    24.Starting this morning, one employee's laptop shows 'Your connection is not private - NET::ERR_CERT_DATE_INVALID' on every HTTPS site, while coworkers on the same network browse normally. What should the technician check first?

    1. A.The router's firewall log for blocked port 443 traffic, since an outbound block shows expired certificates on one laptop.
    2. B.The browser's pop-up blocker settings, since a disabled blocker makes the browser reject certificate dates on secure sites.
    3. C.The laptop's system date, time, and time zone, since a wrong clock makes valid certificates look expired.
    4. D.The DNS A records for the visited sites, since stale records make every site present an expired certificate to this laptop.
    Show answer & explanation

    Correct answer: C — The laptop's system date, time, and time zone, since a wrong clock makes valid certificates look expired.

    • A. Incorrect. A blocked port would stop pages loading, not produce a certificate date warning, and coworkers share the same network path.
    • B. Incorrect. Pop-up blockers have no role in certificate validation.
    • C. Correct. Certificate validity is checked against the local clock, so a wrong date or time zone triggers date errors on every HTTPS site.
    • D. Incorrect. Stale DNS records would send the laptop to a wrong server, not make every site's certificate appear expired only for one user.

    Subdomain 3.1: Given a scenario, troubleshoot common Windows OS issues.

    25.What does the command DISM /Online /Cleanup-Image /RestoreHealth repair that makes it useful before re-running sfc /scannow?

    1. A.The Windows component store, which sfc uses as its source of known-good copies when it replaces damaged system files.
    2. B.The master boot record, which sfc uses to locate the Windows folder before it begins scanning protected system files.
    3. C.The Windows Update client settings, which sfc uses to download missing drivers during every scan of protected files.
    4. D.The user profile registry hives, which sfc uses to compare current desktop settings against the saved default profile.
    Show answer & explanation

    Correct answer: A — The Windows component store, which sfc uses as its source of known-good copies when it replaces damaged system files.

    • A. Correct. DISM RestoreHealth repairs the component store (WinSxS). Because sfc replaces files from that store, a healthy store lets sfc succeed.
    • B. Incorrect. DISM does not alter the master boot record, and sfc does not use it to find files. Boot records are handled by bootrec.
    • C. Incorrect. sfc does not download drivers. DISM can use Windows Update as a source for repair files, but it does not repair update client settings.
    • D. Incorrect. sfc checks protected system files and does not compare profile settings. Profile hives are not repaired by DISM image cleanup.

    Domain 4: Operational Procedures

    Subdomain 4.1: Given a scenario, implement best practices associated with documentation and support systems information management.

    26.A senior employee is leaving the company at the end of the week. The employee has a company laptop, a mobile phone, a badge, and access to several cloud applications. Which document should the help desk follow to make sure nothing is missed on the last day?

    1. A.The internal service-level agreement, which defines how quickly the help desk must respond to tickets submitted by each business department.
    2. B.The user off-boarding checklist, which lists disabling accounts, collecting assigned equipment, and updating the asset record for each returned device.
    3. C.The new user setup checklist, which lists creating accounts, imaging a laptop, and assigning licenses so the replacement can start immediately.
    4. D.The incident report template, which records the timeline, affected systems, and root cause for a security event and is filed after the event closes.
    Show answer & explanation

    Correct answer: B — The user off-boarding checklist, which lists disabling accounts, collecting assigned equipment, and updating the asset record for each returned device.

    • A. Incorrect. An internal SLA sets response and resolution targets between IT and departments; it gives no step-by-step list for closing out a leaver's accounts and devices.
    • B. Correct. An off-boarding checklist ensures access is revoked, equipment is collected, and asset records are updated, so a departing user does not retain access or company property.
    • C. Incorrect. The onboarding checklist covers provisioning for a new hire, not revoking access or recovering equipment from someone leaving.
    • D. Incorrect. An incident report documents a specific event after it happens; a routine departure is not an incident and needs a repeatable process instead.

    Subdomain 4.2: Given a scenario, apply change management procedures.

    27.A technician is preparing to roll out a new endpoint-protection agent to 800 workstations. The change board wants proof that the agent will not break the line-of-business application. What should the technician do first?

    1. A.Push the agent to all 800 workstations overnight and review the helpdesk queue the next morning for reports of application conflicts.
    2. B.Read the vendor's marketing compatibility sheet and paste its claims into the change request as the test evidence for the board.
    3. C.Install the agent on an isolated virtual machine built from the standard image and run the line-of-business application there first.
    4. D.Deploy the agent to the accounting team's production laptops only and wait for those users to open tickets about application problems.
    Show answer & explanation

    Correct answer: C — Install the agent on an isolated virtual machine built from the standard image and run the line-of-business application there first.

    • A. Pushing to every workstation at once is a production rollout, not a test. A conflict would hit 800 users before anyone could contain it.
    • B. A marketing sheet is not test evidence. It does not show how the agent behaves with this company's own image and application.
    • C. Sandbox testing in an isolated environment that mirrors production lets the technician find conflicts without affecting users, and it produces real evidence for the change board.
    • D. Piloting on live laptops exposes real users to possible outages. A sandbox finds the same conflicts before any production machine is touched.

    Subdomain 4.6: Explain the importance of prohibited content/activity and privacy, licensing, and policy concepts.

    28.A technician arrives at a running Windows workstation suspected of hosting malware and must collect evidence before the machine is powered down. Which data should be captured first?

    1. A.Memory contents and running processes, because they are lost the moment the system powers off or restarts
    2. B.Windows event logs on the system drive, because new entries steadily overwrite the oldest recorded events
    3. C.Files stored on the local SSD, because the malicious executables are most likely to be found on disk
    4. D.Archived backup tapes in the off-site vault, because they hold the longest history of changes made to the PC
    Show answer & explanation

    Correct answer: A — Memory contents and running processes, because they are lost the moment the system powers off or restarts

    • A. Correct. RAM and running processes are the most volatile data and vanish at shutdown, so the order of volatility says to capture them before anything stored on disk.
    • B. Incorrect. Event logs live on persistent storage and survive a power-off, so they are less volatile than memory and are collected after it.
    • C. Incorrect. Data on an SSD persists without power, which makes it far less volatile than memory; disk imaging comes later in the collection order.
    • D. Incorrect. Off-site backups are the least volatile source and stay intact regardless of what happens to the workstation, so they are collected last.

    Subdomain 4.7: Given a scenario, use proper communication techniques and professionalism.

    29.A customer says a laptop repair took longer than promised and complains that the company never fixes anything correctly. What should the technician do first?

    1. A.Point out that the original estimate was only approximate and that the delay came from the parts supplier's shipping
    2. B.Refer the customer to the service manager because scheduling decisions are not the responsibility of the technician
    3. C.Let the customer finish, acknowledge the frustration, then explain the current repair status and the next steps
    4. D.Explain that other customers with the same laptop model waited far longer, so this delay is perfectly normal here
    Show answer & explanation

    Correct answer: C — Let the customer finish, acknowledge the frustration, then explain the current repair status and the next steps

    • A. Incorrect. Explaining away the delay by blaming the supplier is defensive, and arguing the point rather than acknowledging the concern tends to escalate an upset customer.
    • B. Incorrect. Handing the complaint off immediately dismisses the customer's issue; the technician should engage with it and escalate only if the customer's needs cannot be met.
    • C. Correct. Listening without interrupting, acknowledging the frustration and then giving status and next steps de-escalates the situation and keeps the focus on resolving the issue.
    • D. Incorrect. Comparing the customer to others minimizes their experience and dismisses their issue, which is the opposite of showing empathy and professionalism.

    Subdomain 4.9: Given a scenario, use remote access technologies.

    30.A technician must administer a Linux web server from the command line over an encrypted channel. Which default TCP port must the firewall allow for this connection?

    1. A.TCP 22
    2. B.TCP 23
    3. C.TCP 3389
    4. D.TCP 5900
    Show answer & explanation

    Correct answer: A — TCP 22

    • A. Secure Shell listens on TCP 22 by default and encrypts the whole command-line session, which makes it the standard way to administer Linux servers remotely.
    • B. TCP 23 is used by Telnet, which sends credentials and commands in clear text and is therefore not an encrypted channel.
    • C. TCP 3389 is the default port for Remote Desktop Protocol, which provides a graphical Windows desktop rather than an SSH command-line session.
    • D. TCP 5900 is the default port for VNC, which shares a graphical desktop and is not the encrypted command-line service described.

    Subdomain 4.10: Explain basic concepts related to artificial intelligence (AI).

    31.A technician uses a generative AI tool to draft a knowledge base article and wants to publish it under their own name without changes. The company's AI policy requires responsible use of generated content. Which action best follows that policy?

    1. A.Edit the draft for accuracy, disclose the AI assistance as policy requires, and check that no passages are copied from existing sources.
    2. B.Publish the draft unchanged, because text generated by an AI tool is always original work and never needs attribution or review.
    3. C.Replace several words with synonyms so plagiarism detectors pass the text, then publish it under the technician's name without disclosure.
    4. D.Run the draft through a spelling and grammar checker, which confirms the facts are correct and removes any copied material automatically.
    Show answer & explanation

    Correct answer: A — Edit the draft for accuracy, disclose the AI assistance as policy requires, and check that no passages are copied from existing sources.

    • A. Correct. Appropriate use means reviewing AI output for accuracy, following disclosure rules, and avoiding plagiarism by checking that content is not copied from other sources. The technician remains responsible for the final article.
    • B. Incorrect. AI output can reproduce existing text and contain errors, so it is not automatically original. Publishing unreviewed text violates responsible-use policy.
    • C. Incorrect. Swapping words to evade detection is still plagiarism and hides AI use that the policy requires disclosing. It also leaves any factual errors in place.
    • D. Incorrect. Spelling and grammar checkers do not verify facts or detect copied passages. They only fix surface-level language errors.

    Subdomain 4.8: Explain the basics of scripting.

    32.A technician will push a script that initiates Windows updates and restarts machines on 200 workstations. Which two actions best reduce the risk of inadvertently changing system settings on production computers?(Select 2)

    1. A.Run the script on all 200 workstations at once during business hours so any problems show up quickly
    2. B.Run the script first on a test virtual machine that mirrors the production image and review the results
    3. C.Disable the antivirus agent on every workstation while the script runs so it does not block commands
    4. D.Embed the domain administrator password in plain text inside the script so it never prompts for credentials
    5. E.Comment each setting the script changes and keep a rollback script that restores the original values
    Show answer & explanation

    Correct answers: B, E — Run the script first on a test virtual machine that mirrors the production image and review the results; Comment each setting the script changes and keep a rollback script that restores the original values

    • A. Running on every machine at once spreads any mistake to the whole fleet, and users bear the impact. Changes should be proven on a small group first.
    • B. A test virtual machine mirroring production shows what the script really changes without risking live computers. Reviewing the results catches unwanted settings changes early.
    • C. Turning off antivirus removes a safeguard and invites malware while the script runs. It does nothing to control which settings the script modifies.
    • D. A plain-text administrator password can be read by anyone who opens the script, which creates a security hole. It also does not limit what the script changes.
    • E. Comments document every setting touched, and a rollback script lets the technician undo unwanted changes quickly. Both limit the damage of inadvertent changes.

    Subdomain 4.3: Given a scenario, implement workstation backup and recovery methods.

    33.What is a synthetic full backup?

    1. A.A full backup built on the backup server by merging the last full with incrementals, without rereading the workstation
    2. B.A full backup taken from a virtual machine snapshot so the guest operating system is never paused during the copy operation
    3. C.A differential backup that clears the archive attribute on every file so the next job copies only newly created files
    4. D.A full backup compressed and encrypted on the source workstation before it is sent to offsite or cloud storage targets
    Show answer & explanation

    Correct answer: A — A full backup built on the backup server by merging the last full with incrementals, without rereading the workstation

    • A. A synthetic full is built on the backup server by merging the previous full backup with the incrementals that followed it. This yields a new full restore point without reading all the data from the workstation again, which saves time and network load.
    • B. Snapshot-based backups of virtual machines are a different technique. The term synthetic refers to how the full set is constructed from existing backups, not to pausing a guest.
    • C. A differential backup copies changes since the last full backup and does not clear the archive attribute. It is also not a full backup, so it cannot be called synthetic.
    • D. Compression and encryption at the source describe how data is protected in transit and at rest. They do not define how a synthetic full is created.

    Subdomain 4.4: Given a scenario, use common safety procedures.

    34.A technician has to clear dust and debris from the inside of several desktop PCs in a dusty storage room using compressed air. Which TWO items best protect the technician's personal safety during this work?(Select 2)

    1. A.Safety goggles to keep flying debris out of the eyes
    2. B.An air filter mask to avoid inhaling dust and fine particles
    3. C.A rubber apron to shield clothing from static discharge
    4. D.Insulated gloves rated for use on high-voltage panels
    5. E.Ear plugs to block fan noise from the nearby workstations
    Show answer & explanation

    Correct answers: A, B — Safety goggles to keep flying debris out of the eyes; An air filter mask to avoid inhaling dust and fine particles

    • A. Correct. Compressed air launches particles at high speed, so goggles protect the eyes from debris.
    • B. Correct. Dislodged dust becomes airborne and a filter mask keeps the technician from breathing it in.
    • C. Incorrect. An apron does not address the hazards of airborne dust, and static protection is provided by wrist straps and mats rather than clothing covers.
    • D. Incorrect. High-voltage gloves protect against electrical hazards, which are not present when cleaning an unplugged PC with compressed air.
    • E. Incorrect. Fan noise is not the main hazard during cleaning, so hearing protection does not address the particles and debris being released.

    Subdomain 4.5: Summarize environmental impacts and local environment controls.

    35.A technician must remove heavy dust from the inside of a desktop PC and its case fans. Which TWO practices are correct?(Select 2)

    1. A.Tilt the compressed air can upside down and spray continuously so the blast is stronger inside the case
    2. B.Power off and unplug the PC, then blow dust out in short bursts while holding each fan blade still
    3. C.Run a standard household vacuum with a plastic nozzle directly across the motherboard and expansion cards
    4. D.Leave the PC running so the spinning fans carry the dust out through the exhaust vent as it is blown
    5. E.Use an ESD-safe vacuum designed for electronics to remove dust from the case, filters, and heat sink fins
    Show answer & explanation

    Correct answers: B, E — Power off and unplug the PC, then blow dust out in short bursts while holding each fan blade still; Use an ESD-safe vacuum designed for electronics to remove dust from the case, filters, and heat sink fins

    • A. Incorrect. Holding the can upside down releases the liquid propellant, which can freeze or wet components. Cans should be kept upright and used in short bursts.
    • B. Correct. Cleaning is done with power removed, and holding the fan blades still prevents over-spinning that could damage the bearings or generate a back-voltage on the board.
    • C. Incorrect. Ordinary household vacuums and plastic nozzles generate static electricity that can damage sensitive components, so only ESD-safe vacuums are suitable.
    • D. Incorrect. Working on a powered system risks shorts and shocks, and free-spinning fans driven by compressed air can be damaged.
    • E. Correct. An ESD-safe vacuum pulls dust away without building up static charge, which makes it suitable for the case, filters, and heat sink fins.

    Want the full experience?

    These are just samples. Practice the full CompTIA A+ Core 2 question bank in quiz mode — free, no signup, with domain practice and exam simulation.