Free CompTIA A+ practice test
60 original questions written to the current A+ objectives — 30 for Core 1 and 30 for Core 2. Pick a core, answer each question, and read the explanation the moment you do. No signup, nothing to download.
CompTIA A+ Core 1 (220-1201) practice test — 30 questions
A small business needs to run an application that depends on 16-bit components on a new laptop with 64-bit Windows. The app fails to launch. What is the BEST solution?
Very old 16-bit applications will not run natively on 64-bit Windows because 64-bit Windows lacks the compatibility layer needed to execute 16-bit code. The best fix is to run the app in a virtualized legacy environment, such as a virtual machine hosting a compatible older operating system, or to keep a dedicated legacy machine. Reinstalling the 64-bit application is not possible because the software depends on 16-bit components and no 64-bit version exists in this scenario. Updating 64-bit device drivers does not help because the problem is application-level code compatibility, not a driver issue. Increasing the system page file addresses memory paging performance and has nothing to do with the inability to execute 16-bit instructions. The key concept is that while a 64-bit OS can generally run 32-bit applications through a compatibility layer, 16-bit code is not supported natively, and virtualization is the standard workaround.
A user reports that VirtualBox displays an error and refuses to launch any 64-bit virtual machines, even though the computer has a capable multi-core Intel processor and plenty of RAM. Which firmware setting should the technician enable to resolve this issue?
Hardware virtualization must be enabled in firmware before virtualization software can run virtual machines. On Intel systems this feature is called Intel Virtualization Technology, or VT-x (on AMD systems it is called AMD-V or SVM Mode). When it is disabled, applications like VirtualBox, VMware, Hyper-V, and Android emulators fail to start virtual machines even when the CPU fully supports the feature. This is a very common support issue because a capable processor alone is not enough; the setting must be turned on in BIOS or UEFI. Secure Boot is a security feature that ensures only trusted boot software loads during startup; it does not control virtualization and would not cause this error. A Trusted Platform Module (TPM) protects encryption keys and supports drive encryption and system integrity, but it plays no role in running virtual machines. The Compatibility Support Module (CSM) allows a UEFI system to boot older BIOS-style operating systems and tools; it affects boot compatibility, not virtualization capability. The correct fix is to enter firmware settings and enable Intel VT-x.
A small business server is experiencing random file corruption over long uptimes. The hardware supports ECC memory. Which RAM choice best addresses this issue?
ECC memory can detect and correct certain memory bit errors that would otherwise corrupt data. When the platform supports it, ECC is the appropriate choice for systems where stability and data integrity are critical.
An external USB optical drive intermittently fails to eject discs and spins down during use. The drive works correctly when connected directly to a desktop PC. What is the most likely cause?
A bus-powered external optical drive can draw more current than one laptop or hub port reliably supplies, so the motor spins down and the eject mechanism stalls, while a desktop port that delivers full power works normally; a USB Y-cable, a powered hub, or the drive's optional power adapter fixes it. A region-code mismatch blocks playback of a DVD movie but does not stall the motor or the eject. An unsupported disc format returns a read error rather than intermittent spin-down. Outdated firmware would misbehave identically on the desktop, which the drive does not.
A technician is explaining how a power supply handles electricity. Which statement correctly distinguishes input voltage from output voltage?
Input voltage is what the power supply receives from the wall outlet, which is where 110-120 VAC and 220-240 VAC apply. Output voltage is what the PSU sends to the computer components as DC power, which is where 3.3V, 5V, and 12V apply. The choice stating input is the DC rails and output is 120V AC has these reversed, since the low DC voltages are outputs and 120V AC is an input. The choice claiming input is sent to components and output comes from the wall also reverses the definitions. The statement that both input and output are measured in VAC is wrong because the output is direct current (DC), not alternating current; only the input from the wall is AC. Keeping input and output separate is essential: a PSU may receive 120V AC in one country or 230V AC in another, yet still output the same 3.3V, 5V, and 12V DC internally.
A help desk technician connects a desktop PC to an older classroom projector using an HDMI-to-VGA adapter. The projector powers on, but the screen remains black. The HDMI cable and VGA cable both test good. Which explanation best fits this scenario?
HDMI outputs a digital signal, while VGA expects an analog signal. Converting from digital to analog typically requires an active adapter with electronics to perform the conversion. A passive HDMI-to-VGA adapter often results in a black screen even when cables appear functional.
A gamer reports that on their new monitor, moving objects leave a noticeable trailing smear during dark scenes and while scrolling high-contrast text. The user is otherwise happy with deeper blacks than their old screen. Which LCD panel type is most consistent with this motion complaint?
The symptom describes motion smearing or ghosting, especially in dark scenes, along with the benefit of deeper blacks. VA panels are noted for stronger contrast but can have slower pixel transitions in darker ranges, which can appear as smearing during motion.
A technician is examining a motherboard and sees a very short expansion slot used for a Wi-Fi card. Which slot type is this MOST likely to be?
A PCIe x1 slot is very short and is commonly used for low-bandwidth cards such as Wi-Fi adapters, sound cards, USB expansion cards, and small NICs. On most boards the physical slot length matches the lane count, so a very short slot signals x1. A PCIe x16 slot is a long slot, most often used for a graphics card, and would be far too long for a small Wi-Fi card. A legacy PCI slot is long, typically has a single key notch, and lacks lane labels like x1 or x16, so it does not match a short modern slot. A PCIe x8 slot is mid-length and is generally used for higher-end NICs, RAID/HBA cards, or workstation add-ins, not a short Wi-Fi card slot. Remember that a smaller card can fit in a larger slot, but the reverse is not true, so identifying the short slot as x1 aligns with both the physical length and the typical low-bandwidth use case.
A user complains that their wireless earbuds keep disconnecting from their smartphone while walking around the house. Which type of network is being used between the earbuds and the phone?
A personal area network (PAN) is a small network built around an individual and their devices, typically covering only a short distance such as the area around a user's body or desk. PAN connections commonly use Bluetooth, NFC, or USB, which is exactly what wireless earbuds use to communicate with a smartphone. When earbuds disconnect while a user moves around, the issue is usually PAN-related, such as exceeding Bluetooth range or low battery levels. A LAN (local area network) connects devices within a limited area like a home or office using Ethernet, switches, and routers, not short-range accessory pairing. A WLAN (wireless local area network) is a local network that uses Wi-Fi and wireless access points to connect devices like laptops and tablets to a wired network, not to pair small accessories. A MAN (metropolitan area network) connects networks across a city or large campus and is far larger in scope than a connection between two personal devices. Recognizing this as a PAN helps a technician focus troubleshooting on Bluetooth pairing, range, and battery power.
A technician is terminating a permanent cable run inside a wall between a keystone jack and a patch panel. Which type of conductor construction is the BEST choice for this installation?
Solid copper conductors are preferred for permanent building cabling because they provide better electrical performance across long distances, lower resistance, better PoE power delivery, reliable punchdown termination, and lower signal loss. This makes solid conductors ideal for runs inside walls between keystone jacks and patch panels. Stranded copper conductors are more flexible and withstand repeated movement, making them suited for patch cables that connect devices, but they have slightly greater resistance and signal loss and are not ideal for permanent runs. Copper-clad aluminum has greater electrical resistance, is more fragile, and may perform poorly with Power over Ethernet, so it should be avoided in reliable installations. Stranded copper-clad aluminum combines the weaknesses of both flexible construction and inferior conductor material, making it the least suitable option for a permanent run. Technicians should remember that connectors must also match the conductor type, since some RJ45 plugs are designed for solid cable and others for stranded cable, and using the wrong connector can create an unreliable connection. Solid cable is relatively stiff and repeated bending can weaken or break it, so it should remain fixed after installation rather than being flexed or plugged directly into user devices.
A technician installs a new IP security camera on an exterior wall that has no nearby electrical outlet. The camera has a single RJ45 port and no separate power connector. Which technology allows the camera to receive both its network connection and electrical power through one Ethernet cable?
Power over Ethernet (PoE) allows a single Ethernet cable to carry both direct-current electrical power and network data at the same time. This is ideal for devices such as security cameras, access points, and VoIP phones installed in locations where a standard power outlet is unavailable or inconvenient. The device supplying power is the power-sourcing equipment, and the camera is the powered device. Auto-MDI/MDIX is a feature that automatically detects and adjusts the transmit and receive pin assignments so that straight-through or crossover cables can be used interchangeably, but it does not supply power. Link aggregation combines multiple physical links into one logical connection to increase bandwidth or provide redundancy, which has nothing to do with powering a device. Network Address Translation is a router function that translates private IP addresses to a public address for internet access and does not deliver electrical power. Only PoE combines both power and data on the same twisted-pair cable, making it the correct choice for powering a camera over a single Ethernet run.
While setting up a new fiber-based SOHO network, a technician finds that no devices can reach the internet. The provider's fiber line terminates at an ONT, and the technician discovers the ONT's Ethernet cable is plugged into one of the router's LAN ports. What is the correct fix?
In a SOHO network the modem or ONT must connect to the router's WAN (internet) port, which separates the provider-facing connection from the private local network. A common cabling mistake is connecting the ONT to one of the router's LAN ports instead of the WAN port, which prevents the router from establishing its internet connection and performing NAT for local devices; moving the cable to the WAN port restores the correct path of provider fiber, then ONT, then router WAN port. Moving the cable to a switch uplink port is wrong because the switch only expands local wired ports and does not provide routing, NAT, or the WAN internet connection. Enabling DHCP on the ONT does not help; the ONT converts the optical signal to Ethernet, while the router provides DHCP to the LAN, and the problem is the physical port, not addressing. Replacing LAN ports with PoE ports is not a real fix, since PoE supplies power rather than establishing the internet path.
You are designing Wi-Fi coverage for a large single-story warehouse with thick interior walls and long aisles. The business requires reliable connectivity for low-bandwidth IoT sensors spread throughout the building, and many of the sensors support only older Wi-Fi hardware. Which approach BEST aligns with these constraints?
Lower frequencies travel farther and pass through walls better, and 2.4 GHz is supported by virtually every Wi-Fi device including old and low-cost IoT hardware, so it fits a large building full of legacy sensors. 5 GHz for range is wrong because 5 GHz has shorter range and worse penetration than 2.4 GHz. 6 GHz is wrong because, although it does have the most channels, its range is the shortest of the three and only Wi-Fi 6E and 7 clients can use it, so the older sensors could not connect at all. 5 GHz for universal compatibility is wrong because many IoT and legacy devices are 2.4 GHz only.
A firewall audit reveals that legacy Windows name resolution traffic is still allowed. Which ports are associated with this legacy service and commonly blocked due to security concerns?
NetBIOS over TCP/IP uses ports 137, 138, and 139 for name resolution and session services. These ports are considered insecure and are often blocked in modern networks.
Two employees are connected to ports on the same managed switch but cannot communicate with each other, even though both devices have valid IP addresses in the same subnet and both can reach the internet. No firewall rules are blocking traffic. What is the MOST likely explanation?
Two hosts in the same subnet should talk directly through the switch at Layer 2; if they cannot, the switch is keeping them apart, and VLAN assignment is how a managed switch does that. Devices in different VLANs cannot reach each other without a router or Layer 3 switch performing inter-VLAN routing. Duplicate MAC entries are not a normal switch configuration and would cause flapping, not clean isolation. Mismatched port speeds still pass traffic (the switch buffers between them). If spanning tree had disabled the ports, neither device could reach the internet either.
A technician is advising a customer choosing between two Android smartphones: one with 4GB LPDDR5 RAM and another with 8GB LPDDR4 RAM. The customer primarily multitasks with social media, web browsing, and photo editing. Which recommendation BEST aligns with real-world performance expectations?
For typical multitasking, RAM capacity has a greater impact than raw speed. An 8GB LPDDR4 device will keep more applications resident in memory compared to a 4GB LPDDR5 device, resulting in smoother real-world performance.
A mobile user complains that Bluetooth tethering disconnects whenever the phone screen turns off. Cellular coverage is stable and devices are within range. What configuration is MOST likely causing this issue?
Some battery-saver profiles switch Bluetooth off or suspend its connections when the screen turns off, which drops the tethering session each time the phone idles. A carrier data cap would slow or block data, not disconnect exactly when the screen sleeps. The hotspot band setting applies to Wi-Fi hotspots and has no effect on a Bluetooth PAN link. A PAN profile mismatch would prevent the connection from ever forming rather than dropping it on idle.
A user notices that the status bar on their new phone shows 5G while walking outside but switches to LTE once they are inside the office. Calls and data continue to work in both places. What is the MOST likely explanation?
5G coverage is often patchy indoors, and phones automatically fall back to 4G LTE when the 5G signal is lost, which is normal and requires no action. A SIM without 5G provisioning would never show 5G, even outdoors. Data roaming controls use of other carriers’ networks and has nothing to do with moving indoors. Airplane mode is all-or-nothing for the cellular radio; it cannot switch off 5G alone.
A mobile device uses a unified memory architecture where the CPU and GPU share the same RAM pool. The user notices reduced available RAM during gaming sessions. What explains this behavior?
In unified memory architectures, the GPU dynamically uses system RAM for graphics processing during intensive workloads like gaming. This reduces RAM available to applications temporarily but allows flexible allocation based on demand.
An office already uses proximity badges for door access. Management wants print jobs sent to the shared MFD to stay hidden until the person who sent them taps that same badge at the device. What must be added to make this work?
Badge release is secured printing where the release credential is the user's existing proximity or smart card: a reader is attached to the MFD and each badge's ID is enrolled against the user's account (by self-registration on first tap or an import from the access-control system), so a tap identifies the user and releases their held jobs. A PIN prompt is PIN release, which holds jobs but does not use the badge. A separate printer-only badge defeats the goal of reusing the door badge, and a door-access controller secures a room, not the jobs waiting on the device.
A shared office laser printer begins producing faded text across all pages, but there are no error messages. As the technician, you want to confirm the most likely maintenance action before replacing any long-life parts. What should you do first?
Light or faded print is most commonly associated with low toner levels or a toner cartridge that is not seated correctly. The recommended maintenance flow starts with checking and replacing consumables like toner before moving on to calibration or installing a maintenance kit. Cleaning or handling the fuser is unnecessary at this stage and carries added heat risk.
A user says, “The VDI desktop is fine, but my USB scanner isn’t available inside the session.” The VDI team confirms the virtual desktop VM is healthy. As a front-line A+ technician, what is the best next step aligned with VDI quick troubleshooting?
Peripheral issues in VDI often require endpoint-side validation because devices like scanners, printers, webcams, and headsets can fail even when the hosted desktop is healthy. A practical first step is to verify the scanner functions locally, reconnect the USB device, and confirm it works outside VDI. This isolates whether the failure is endpoint/peripheral-related before escalating to server-side teams.
A company receives a higher-than-expected cloud bill after publishing large training videos. Most viewers streamed or downloaded the videos from cloud storage to their devices. Which metered utilization category most directly drove the unexpected charge?
Egress is data leaving the cloud service to users, the internet, or other sites. Streaming and downloads push content out from cloud storage, which can drive metered network charges. Ingress refers to uploads into the cloud and would not be the primary cost driver for user downloads.
A technician is triaging VDI login failures. One user reports repeated sign-in prompts and certificate-related errors on the VDI web portal, while other users in the same site are able to log in normally. Which quick check is most likely to resolve this single-user issue without escalating?
Incorrect time and date on an endpoint can disrupt sign-in flows that rely on certificates and multi-factor authentication prompts. When the issue is isolated to one user while others can log in, checking the endpoint’s time and date is a fast, high-value step that can restore authentication behavior without changing server capacity, storage performance, or desktop assignment type.
A desktop with integrated graphics (no discrete card) powers on with spinning fans, but no logo or cursor ever appears on the display. The monitor power light is on and no beeps are heard. Based on structured blank-screen troubleshooting, what is the BEST first hardware-focused action?
No logo or cursor with fans running suggests a no-video during POST scenario rather than an OS failure. The correct next step is isolating the display path and core POST components by reseating RAM and testing with a known-good monitor or cable. Operating system repairs are premature because the system has not demonstrated successful POST or boot handoff.
A technician installs a second SATA SSD in a desktop. The UEFI setup lists the drive under storage devices, but it does not appear in File Explorer. What should the technician do NEXT?
Firmware detection proves the cabling, port, and drive hardware are working; a brand-new drive is simply uninitialized, so Windows cannot show it in File Explorer until Disk Management initializes it (GPT), creates a partition, formats it, and assigns a drive letter. Reseating cables or enabling the port are the fixes when the drive is missing from firmware, which it is not. Replacing a drive that the system detects normally is unnecessary.
A user reports no audio after connecting to a monitor via HDMI. The monitor image is normal, but the user expects sound from the laptop speakers. What is the BEST next step consistent with Objective 5.3?
HDMI and DisplayPort can carry audio, so connecting a display can cause the system to switch the default audio output to the monitor or projector without the user realizing it. The best first step is to verify mute/volume and then select the intended playback device (laptop speakers, headset, or HDMI device) in the operating system before replacing cables or hardware.
A user cannot install any new apps. The device also feels slower than usual and recently displayed storage warnings. What is the BEST next troubleshooting step before changing accounts or performing resets?
Low storage is a common, high-impact root cause that can block downloads, unpacking, updates, and normal performance. Checking and reclaiming storage is a safe, fast, and testable step that often resolves both install failures and sluggish behavior. Account changes or factory resets are higher risk and should come after basics like storage and connectivity are confirmed.
A user reports intermittent Wi-Fi drops that correlate with lunchtime in a crowded office. Ethernet is stable. What is the BEST next change that is low-risk and most likely to improve stability?
Peak-hour Wi-Fi issues with stable Ethernet typically indicate RF contention/congestion and interference. The most exam-aligned, low-risk improvement is optimizing Wi-Fi band/channel use (prefer 5/6 GHz for capacity; avoid overlapping 2.4 GHz channels; use sensible channel widths).
A laser printer shows faint “ghost” images (a lighter duplicate of text shifted slightly down the page). The issue worsens when printing on heavier paper stock. What is the MOST likely cause?
Ghosting on a laser printer comes from one of two places: an imaging drum that was not fully cleaned between rotations, or a fuser that did not lock the toner down. The cue here is that the ghost worsens on heavier paper stock. Paper weight changes fusing (heavier stock needs more heat and a slower speed), not drum cleaning, so the fuser is the more likely cause; check the media-type setting and eco mode, then replace the fuser or maintenance kit. A worn drum cleaning blade is the classic answer when the ghost is identical on every paper type and repeats at the drum circumference, but it would not get worse specifically on heavy stock. A failing transfer roller produces light or blotchy print, and a contaminated corona wire produces lines or an overall gray background, neither of which is an offset duplicate image.
CompTIA A+ Core 2 (220-1202) practice test — 30 questions
A user is trying to copy a 6 GB movie file from their Windows laptop to a USB flash drive, but the transfer fails even though the drive shows 40 GB of free space. Which of the following is the MOST likely cause of the failure?
FAT32 has a maximum single-file size limit of 4 GB. When a user attempts to copy a 6 GB file, the transfer fails regardless of how much free space the drive has because the filesystem simply cannot represent a file larger than the 4 GB cap. This is one of the most common real-world storage failures. exFAT was specifically designed to remove the FAT32 file-size limit, so it easily handles large media files and would not cause this failure. NTFS also supports very large files and volumes, so it would allow the 6 GB copy to complete successfully. ReFS is a resilient filesystem focused on data integrity for large storage pools and Storage Spaces; it also supports large files and is not used on typical USB flash drives. A helpful memory hook is 'FAT32 fails at 4, exFAT fits, NTFS locks.' To resolve this situation, the technician would reformat the drive as exFAT for broad cross-platform compatibility with large files, or NTFS if Windows-specific permissions are needed.
Which recovery option reinstalls Windows and rebuilds system files while keeping the files stored in the user's profile?
Reset this PC (Keep my files) is correct because it reinstalls Windows and rebuilds system files while preserving user files in the profile, typically located in C:\Users. It is a good fit when the OS feels unstable, malware is unlikely, and the user's data must remain. However, it still removes most applications, many settings, and custom drivers, so the technician should plan time to reinstall software afterward. Reset this PC (Remove everything) is incorrect because it wipes Windows and reinstalls clean, removing files, apps, settings, and local accounts; it fits device re-assignment or suspected compromise rather than preserving user data. OEM factory recovery is incorrect because it restores the device to factory state, often including vendor apps, trial software, and custom partitions, rather than simply keeping the user's current files. Startup Repair is incorrect because it is an advanced startup tool that fixes boot problems and rolls back recent changes; it does not reinstall Windows or rebuild system files in the same way, and it is best used for boot loops after updates or a bad driver install.
In a small business, IT staff need to remotely connect INTO users' desktops after hours using Microsoft's built-in Remote Desktop feature. The devices currently run Windows 11 Home. What is the limitation the technician must address?
Most Windows editions include the ability to act as an RDP client, meaning they can connect out to another PC, but Windows Home cannot act as an RDP host using Microsoft's built-in feature, so it cannot accept incoming Remote Desktop connections. This single difference is what drives many small-business upgrade requests to Pro, which supports RDP hosting. The claim that Home supports RDP hosting only over a wired connection is incorrect because Home does not support inbound RDP hosting at all, regardless of network medium. The idea that Home blocks RDP until BitLocker is enabled is false, since encryption status has no bearing on RDP host capability, and Home does not fully support BitLocker management anyway. The statement that Home allows RDP hosting limited to one user is wrong because Home does not provide the host role in the first place. When RDP hosting is unavailable, support teams often use approved alternatives such as Quick Assist or third-party remote tools, but if the organization requires native RDP hosting, upgrading to Windows Pro is the correct fix.
A printer stops working on a workstation, but the user's applications otherwise run normally. Rather than rebooting the entire PC, which Task Manager tab and action can restore the feature with the least disruption?
The Services tab lists background Windows components that support the OS and installed software, and restarting the related service, such as the print spooler, can restore a failed feature without the disruption of a full reboot. This is the safe, targeted action when a specific function fails while the user's apps run fine. Using End task on a print app in the Processes tab only closes the visible application and does not restart the underlying service that actually handles printing, so the feature is likely to remain broken. Disabling the printer's startup entry in the Startup tab would prevent a helper from launching at sign-in and would not restart a currently stopped service; it could even remove functionality the user needs. Opening Resource Monitor from the Performance tab provides deeper performance data on disk queues and per-process activity, but it is a diagnostic view, not a way to restart a service and restore printing. Because the goal is to bring the feature back with minimal impact, restarting the associated service from the Services tab is the correct choice.
A user insists that a downloaded file has vanished from a folder that appears empty in File Explorer. A technician wants to confirm from the command line whether any hidden files exist in that directory. Which command should the technician run?
The dir /a switch displays items with special attributes, including hidden and system files, which is exactly what is needed when a folder looks empty but may still contain files that are not shown in normal views. The dir /w switch produces a wide format that lists names in columns to make scanning faster, but it does not reveal hidden files. The dir /p switch pauses output one screen at a time so long listings do not scroll past, which helps readability but does not expose hidden items. The dir /s switch searches the current folder and all of its subfolders, which is useful for locating a filename across a directory tree but will not show hidden files in the current directory unless combined with /a. When a folder mysteriously appears empty, /a is the correct first step to confirm what truly exists before assuming a file was deleted.
A technician needs to confirm the reason a workstation restarted unexpectedly overnight. Which Administrative Tool should the technician open to locate a time-stamped record of the shutdown cause?
Event Viewer records system and application events, and the System log is where an unexplained restart becomes actionable through a time-stamped shutdown reason or a logged driver failure. Filtering by time range and severity such as Error or Critical helps focus on what changed near the incident. Task Scheduler manages tasks that run on a schedule or trigger, such as scripts or updaters at logon, but it does not record why a PC restarted. Device Manager shows hardware and driver status and is used for tasks like rolling back a driver, not for reviewing shutdown history. Disk Management focuses on partitions and drive letters, so it would help with a missing volume, not a reboot investigation. Choosing the tool that matches the symptom and confirming the cause before changing settings is the correct troubleshooting habit.
In a workgroup environment, an employee named Kim leaves the company. Her local account still exists on PC-3, which hosts a shared folder at \\PC-3\Projects. Which statement BEST describes the offboarding challenge?
In a workgroup, accounts are local to each individual PC, so there is no central directory to disable. To fully offboard Kim, a technician must disable or delete her account on every machine, remove saved credentials, and update permissions on each shared folder, making it a repetitive checklist task. Disabling one central account only applies to a domain, where a directory such as Active Directory stores identities centrally; workgroups have no such central identity store. Group Policy is a domain feature that pushes and enforces rules on domain-joined PCs, so it does not exist to automatically revoke permissions in a workgroup. Updating a print server does not apply because workgroups typically share printers directly from a host PC using local credentials rather than from a centralized print server. This scenario illustrates why exam wording like 'remove access everywhere' points to a domain account action, while per-PC cleanup is the hallmark of workgroup offboarding. The lack of centralized control is one of the biggest security weaknesses of workgroups as they grow.
An employee leaves the company, and IT attempts to erase and redeploy their company-owned iPhone. The device demands the previous user's Apple ID and password before it can be reactivated, but no one has the credentials. Which feature is preventing the device from being reused?
Activation Lock is tied to the Find My feature. When a user signs in and enables Find My, the device can require that Apple ID and password before anyone can erase and re-activate it. This protects against theft, but it also blocks legitimate reuse when an employee leaves and no one knows the credentials. That is exactly why organizations avoid personal Apple IDs on recoverable hardware and configure MDM to support Activation Lock management. Screen Time is a parental-control and usage feature that can limit account changes and content, but it does not lock a device to a specific Apple ID during reactivation. iCloud Keychain is a password-syncing service that stores credentials across devices; it has no role in blocking device erasure or reactivation. Rapid Security Response is a fast Apple security patch delivered between full OS updates; it does not require credentials to reuse a device. The key takeaway is to treat Apple ID sign-in as a controlled provisioning step so that Activation Lock surprises do not turn a normal offboarding into unusable hardware sitting on a shelf.
A technician needs to set permissions on a shell script so that the owner has full access while the group and all other users can only read and execute it. Which command achieves this using numeric mode?
In numeric mode, read equals 4, write equals 2, and execute equals 1, and the values are added per identity group in the order owner, group, others. The command chmod 755 script.sh gives the owner 7 (read + write + execute = full access), and both group and others 5 (read + execute), which exactly matches the requirement. The command chmod 644 script.sh gives the owner read and write and everyone else read only, but it grants no execute permission, so the script could not be run and does not meet the requirement. The command chmod 777 script.sh grants everyone full read, write, and execute rights, which is excessive, a security risk, and more than what was requested. The command chmod 700 script.sh gives the owner full access but denies the group and others any access at all, so they could not read or execute the script. The 755 pattern is common because it fits scripts and programs that others need to run but not modify.
A facility is planning biometric access for a cold-storage warehouse where staff frequently wear gloves and hands are often dirty. Which concern is MOST relevant when choosing a fingerprint scanner for this environment?
Fingerprint scanners rely on contact with the sensor, so gloves block that contact and dust, grime, lotion, or wet hands can reduce read quality. In a cold-storage warehouse where staff wear gloves and hands are often dirty, these environmental factors would cause frequent false rejects and increase help desk calls, making a fallback method such as a PIN or badge important. The claim that fingerprints cannot be enrolled for warehouse staff is inaccurate; enrollment is possible, though some individuals with worn fingerprints may have lower read success, which is a separate issue from the primary glove and grime concern. Fingerprint readers do not require a cellular signal, because matching occurs locally at the reader, so connectivity is not the relevant limitation here. The statement that fingerprint data automatically grants admin permissions is false, since biometrics identify a person, not a permission; access rules, logging, and group membership still determine what the authenticated user is allowed to do. When choosing biometrics, teams must account for the real environment and always plan a safe fallback so that access does not fail during normal work.
A traveling sales representative uses one Windows 11 laptop that is not domain-joined. The rep wants browser favorites and Windows settings to follow them onto a replacement laptop and wants to be able to recover a forgotten password from any device without calling IT. Which sign-in account type BEST fits?
A Microsoft account ties the sign-in to a cloud identity, so settings and browser data sync to any device the user signs in to, and the password can be reset online from a phone or another PC. A local account with security questions can be recovered only at that one PC, and nothing syncs to a replacement laptop. A domain account with a roaming profile does provide a profile that follows the user, but the laptop is not domain-joined and roaming profiles require an on-premises domain controller and file server, which a traveling rep rarely reaches. The Guest account is disabled by default, has no password, and keeps no persistent settings, so it cannot provide recovery or sync. Choose a local account for kiosks, labs, and offline systems; choose a Microsoft account when identity, recovery, and settings should follow a single user through the cloud.
During a security audit, a technician needs to confirm which port and transport protocol a TACACS+ server uses. Which of the following is correct?
TACACS+ uses TCP port 49, and this is a frequently tested fact. TCP provides reliable, ordered delivery, which is valuable during administrative logins where interruptions could cause confusing states or outages. UDP port 1812 is incorrect because that port and transport are associated with RADIUS authentication, not TACACS+. UDP port 49 is incorrect because although the port number 49 is associated with TACACS+, the protocol uses TCP rather than UDP. TCP port 1813 is incorrect because port 1813 is used for RADIUS accounting, not TACACS+. Remembering that TACACS+ pairs TCP with port 49 helps distinguish it from RADIUS, which uses UDP with ports 1812 for authentication and 1813 for accounting.
A technician suspects a rootkit on a workstation because the user reports account lockouts and browser hijacks, yet a standard on-access antivirus scan reports 'nothing found.' Which action gives the technician the BEST chance of accurately detecting the threat?
A rootkit focuses on stealth and control, often operating at a deep level such as the kernel where it can intercept system calls and mask files, processes, or registry entries. Because it can hide from tools running inside the infected environment, an offline scan is the best approach: the technician boots into a trusted scanner and inspects the disk from the outside, so the rootkit is not running to conceal itself. Increasing the frequency of quick scans does not help, because a quick scan checks common locations while still relying on the compromised, running operating system that the rootkit is manipulating. Disabling real-time protection weakens the endpoint and still leaves the scanner dependent on the tampered environment, so it will not reliably reveal a kernel-level rootkit. Restoring the browser homepage and default search engine only addresses one visible symptom of a hijack and does nothing to detect or remove the underlying rootkit, which will simply reapply its changes. When strong signs of compromise appear but tools report clean, suspect stealthy malware and move detection outside the infected OS.
During a suspected DoS incident affecting a company web server, an entry-level technician wants to help. Which action is the MOST appropriate first step?
During a suspected denial of service incident, entry-level staff add the most value through calm triage and strong documentation. Recording timestamps, symptoms, affected services, and error messages, then escalating through the approved path, preserves evidence and helps the response team act faster while confirming the scope. Rebooting the server to clear the condition is a common mistake because a restart can erase useful logs and delay a clean handoff to the network or security team, and it rarely stops an ongoing flood. Deleting recent logs to free disk space destroys the exact evidence needed to distinguish a DoS from an ordinary outage and to analyze traffic patterns. Changing all administrator passwords before investigating is out of order; password changes belong after containment, and in an active interception scenario a premature reset could even be captured again. The correct approach is to confirm scope, collect precise details, preserve logs, and escalate quickly rather than taking disruptive actions that could make the situation worse.
A technician is instructing a panicked SOHO user about what to avoid while their infected laptop awaits cleanup. Which instruction should the technician give?
The correct guidance is to tell the user not to log into banks, email, or work accounts and not to plug in USB drives or external storage on the infected machine. Logins risk exposing credentials to keyloggers, and USB drives can spread the infection to other media and devices. 'Log into your bank quickly to change your password from this machine' is dangerous because a keylogger could capture the new credentials; password changes should be done from a clean device instead. 'Click the on-screen scan-now pop-up to remove the threat faster' is wrong because those cleanup ads and fake scan prompts install more malware rather than removing it. 'Pay the ransom immediately so your files can be unlocked' is never advised because paying funds criminal activity and rarely results in file recovery. The technician's role is to calmly stop the user from taking actions that escalate the compromise, reassure them they are not at fault, and keep them from acting alone while the proper cleanup process is followed.
A user complains that the corporate password policy keeps forcing them to change their password, and they simply cycle back to an old password they have used before. A technician needs to prevent users from reusing previous passwords. Which policy setting should be adjusted?
Enforce password history remembers a number of previously used passwords, commonly 10 to 24, so that a user cannot immediately reuse an old favorite when required to change their password. A scenario describing users cycling back to old passwords points directly at this setting. Maximum password age forces a change after a set number of days, which is what triggers the change in the first place, but it does nothing to prevent reuse of an old password. Minimum password length sets the shortest allowable password but places no restriction on reusing a prior one. Account lockout threshold locks an account after a set number of failed sign-in attempts to blunt online brute-force guessing; it is unrelated to password reuse. A related setting, minimum password age, prevents users from changing their password many times in rapid succession to burn through the history list and land back on their original, which complements password history but is not the primary control being asked for here.
A user calls the help desk in a panic saying their iPhone erased all of its data after their toddler repeatedly entered the wrong passcode. Which security feature caused this behavior?
Data erase after failed attempts is a stricter brute-force protection that automatically wipes the device after a defined number of consecutive incorrect passcode entries, commonly ten on iOS when the Erase Data option is enabled. This feature is powerful but blunt, since it cannot distinguish an attacker from a child or a forgetful owner who keeps trying, which is why current remote backups are essential to turn an accidental auto-wipe into a simple restore. Activation lock ties a device to the owner's account so it cannot be reactivated after a wipe, but it does not trigger a wipe itself. Selective wipe removes only managed corporate data such as work email, apps, and profiles while leaving personal content intact, and it is initiated by an administrator, not by failed passcode entries. Lost mode remotely locks the device and displays a custom message and contact number on the lock screen, but it does not erase user data. Understanding that repeated wrong entries can escalate from timed lockouts to a full data erase is exactly the judgment support technicians need when explaining unexpected wipes.
A technician plans to reuse a healthy HDD internally after reinstalling the operating system, but the drive previously held sensitive customer records. The technician performs a full format and considers the drive safe for reuse. Why is this reasoning flawed?
A full format prepares a disk and scans for errors, and on some systems it may write patterns to the disk, but it should not be treated as a guaranteed method to sanitize sensitive data because behavior varies by tool, drive type, and settings. Formatting is an operating system task for readiness, not a security task that targets data recovery risk. Policy usually requires a dedicated, verified wipe before reuse when the drive held sensitive data. The claim that a full format encrypts the old data is incorrect because formatting does not apply encryption; that is a separate crypto-erase concept tied to full-disk encryption. The claim that a full format works only on SSDs is incorrect because formatting applies to both HDDs and SSDs, and neither is reliably sanitized by formatting alone. The claim that a full format degausses the platters is incorrect because degaussing requires a magnetic field device and is entirely separate from a software format. The correct practice is to wipe the drive with an approved overwrite method, verify the result, and only then apply a standard format when preparing it for reuse.
A technician is troubleshooting a desktop where several USB devices repeatedly disconnect after the computer wakes from sleep. The hardware tests fine on another PC. Which setting should the technician adjust FIRST?
When USB devices drop specifically after waking from sleep and the hardware works fine on another machine, the trigger is almost always a power-management state that leaves the controller in a bad condition. Disabling USB selective suspend in Power Options stops Windows from powering down USB ports to save energy, which resolves the repeated wake-and-reconnect loops. Enabling legacy USB support in the BIOS is aimed at older devices misbehaving during early boot, not at sleep/wake disconnects on modern devices. Updating the device firmware is a higher-impact step that is unlikely to matter here, since the same device works normally on another PC, pointing to this system's power settings rather than the device. Switching xHCI mode is a firmware-level change reserved for deeper controller conflicts and should be attempted only after low-risk power settings fail. Following a safe order means starting with the reversible power tweaks that most commonly stop disconnect loops before touching firmware.
A user's Android phone has become extremely slow and multiple apps crash intermittently. The technician wants to determine whether a recently installed third-party app is responsible. Which of the following is the BEST diagnostic step?
Booting into Safe Mode and retesting is the best diagnostic step because Safe Mode starts the phone with most third-party apps disabled. If the slowness and crashes disappear in Safe Mode, a separate app, such as a screen overlay, cleaner, VPN, or accessibility tool, is likely interfering. After confirming, you can restart normally and remove the most recent suspect apps. A factory reset would erase the device and eliminate any chance of identifying the specific culprit, making it far too drastic for a diagnostic step. Clearing the cache for every installed app is a shotgun approach that does not isolate which app is causing the problem and can sign users out of some apps. Resetting network settings targets Wi-Fi, Bluetooth, and VPN configuration issues, which is unrelated to system-wide slowness and app crashes. Safe Mode is a powerful isolation tool specifically valuable for slow response, random reboots, and heavy battery drain because it cleanly separates third-party software from OS-level causes.
During a malware cleanup, a technician disinfects the live system successfully but is concerned the infection could return. According to best-practice removal procedures, which action addresses this risk?
Disabling System Restore to purge existing restore points and then re-enabling it and creating a fresh point is the correct step because restore points are stored in the protected System Volume Information folder, and if the machine was infected when an old point was created, copies of the malicious files can be preserved inside it. Some antivirus scanners cannot fully clean inside restore point storage, so applying an old point could reintroduce the infection. Purging all points removes any snapshot that could re-infect the machine, and creating a new one establishes a known-good clean checkpoint. Rolling back the most recently installed device driver only reverts a single device and does nothing to remove infected snapshots or address malware persistence. Uninstalling the latest quality update and pausing updates targets a problematic Windows patch, which is unrelated to the malware being preserved in restore points. Using the Go back feature returns the machine to a previous Windows version within the ten-day window, which is a feature-update rollback and does not address the malware hiding in restore point storage. This clear-and-recreate step appears in virtually every malware removal procedure precisely because System Restore is not a scanner and an old point may itself be infected.
A technician notices that a personal (non-managed) PC has a proxy server enabled under Windows proxy settings, but the user states they never configured a proxy. Which of the following is the MOST appropriate conclusion?
The proxy is a suspicious indicator of a security issue is the correct conclusion. Adware, malware, and fake 'security' tools frequently set a system-wide proxy so they can watch, modify, or block traffic. On Windows, a proxy configured system-wide affects every browser, which can explain why only web traffic behaves oddly while other apps function differently. When a user on a personal, non-managed device never configured a proxy but one is enabled, it should be treated as a strong clue of compromise. The proxy is a normal default for home networks is incorrect because most home environments require no proxy at all; the correct setting is typically no proxy. The proxy was set automatically by Windows Update is false because Windows Update does not configure proxy servers as part of applying updates. The proxy is required for DHCP to assign an address is also incorrect because DHCP operates independently of proxy settings and assigns IP configuration without any proxy involvement. The appropriate response is to inspect first, then turn off the unneeded proxy, confirm DNS comes from a trusted source, remove suspicious extensions and unknown VPN profiles, and run a trusted scan. If settings reapply after reboot, assume something still has control and keep the device isolated.
A technician wants to see exactly which hub and controller a failing USB device is connected to. Which action in Device Manager provides this hierarchy?
Choosing View by connection from the View menu rearranges Device Manager to display devices in their physical relationship, so the technician can see which USB device sits under which hub and which controller. This makes it far easier to determine whether failures cluster on a single bus. Enabling Show hidden devices exposes ghosted entries from previously connected hardware that still reserve settings, which is useful for cleanup but does not reveal the live connection hierarchy. Choosing Scan for hardware changes forces Windows to re-detect devices and can re-enumerate a device that was removed, but it does not change how the tree is displayed. Opening the device Properties dialog shows the Device status and error code for one specific device, but it does not map the overall parent-child structure of hubs and controllers. Using the connection view is the technique that lets a technician quickly isolate whether the problem follows a device, a hub, or the controller.
A technician is writing an issue description for a ticket about an email problem. Which description is MOST likely to help the next technician verify and act on the issue?
The description stating that the user cannot send in Outlook after a password change with error 0x800CCC0E is clear, complete, and testable because it identifies the symptom, the timing and likely trigger, the exact error code, and enough context to reproduce or verify the problem. Quoting error text exactly is critical because small differences route to different fixes. Saying email is broken and needs fixing ASAP provides no symptom, timeline, or evidence, forcing the next technician to re-ask basic questions and extract facts, which wastes time. Stating that the user is very frustrated captures emotion rather than fact; frustration does not describe what fails, what still works, or what changed, so it is not actionable. Saying something is wrong with the mail server again is a guess presented as a conclusion, mixing assumption with fact and offering no reproducible detail or error text. A good issue description separates symptoms, start time and pattern, what changed, steps to reproduce, and impact. This structure lets any qualified technician confirm the issue, avoid duplicate work, and document a resolution that stands up to review, which also improves handoffs during escalation.
A vendor releases a patch for a vulnerability that is being actively exploited against the company's public web server. The next change advisory board meeting is six days away. Which change type should the technician request?
An emergency change exists for exactly this situation: a fix that cannot wait for the regular review cycle because the risk of not acting (an exploited, internet-facing hole) is greater than the risk of acting quickly. It still needs a named emergency approver and a post-implementation review, but it skips the six-day wait. A standard change is a pre-approved, routine, low-risk task, and patching an actively exploited server under time pressure does not fit that template. A normal change would go through the full board process and the six-day delay. A change freeze is a period when changes are restricted, not a type of change request.
A user reports that their sound card stopped working immediately after Windows automatically updated the audio driver. The computer boots normally and all other devices function correctly. Which of the following is the LEAST destructive way to resolve this issue?
Roll Back Driver is the correct choice because it reverts exactly one device driver to its previously installed version without removing programs, changing the registry system-wide, or touching any other device. When a single device breaks right after a driver update, this surgical tool is the narrowest fix and therefore the least destructive option on the recovery ladder. Performing a System Restore would revert system files, the registry, drivers, and any programs installed since the restore point, making it far more destructive than needed for a single-device problem. Reset this PC with Keep my files removes every installed application and most settings, which is drastically more destructive and only appropriate when the OS itself is too damaged for a rollback. Uninstalling the most recent quality update targets a Windows patch, not a device driver, so it addresses the wrong component entirely and would not restore the previous audio driver. The professional approach is always to read the scenario for the narrowest matching tool: since the problem is clearly isolated to one device after a driver change, driver rollback fixes exactly what broke while preserving everything else.
A technician is about to open a VoIP desk phone that receives power only through its Ethernet cable, and then a laptop that is sitting in a docking station with the charger attached. Neither device has a visible power cord running to a wall outlet. Which of the following steps addresses the hidden power sources before the technician opens the devices?
Power over Ethernet (PoE) and docking stations are the two hidden power sources the objective warns about: a PoE-powered phone or access point is energized by its network cable, and a docked laptop keeps receiving power from the dock and charger even when it appears to be off. Disconnecting the Ethernet cable from the phone and undocking the laptop and unplugging its charger removes both feeds, which is the correct step before opening either device. Holding the reset button only reboots the phone; the PoE feed is still live the moment it comes back up. Shutting the laptop down from the operating system does nothing about the dock, which continues to supply power to the board while the laptop stays connected. Removing the battery is a good step for the laptop but leaves the dock and charger connected and does nothing at all for the phone's PoE feed.
A technician notices the status light on an office surge protector has turned off after a nearby lightning storm, though devices still receive power. What should the technician do?
A surge protector absorbs energy each time it diverts a surge, and its joule rating represents a finite lifetime capacity. A status light that has gone off indicates the protective circuitry, typically metal-oxide varistors, has been depleted, so the strip is now just an ordinary power strip offering no protection. After a major hit such as a lightning storm, the correct action is to replace it. Continuing to use it is unsafe because the equipment is now fully exposed to future surges despite still receiving power. Unplugging it to reset it does nothing because the protective components wear out permanently and cannot be restored by cycling power. Adding a second identical strip in series does not restore protection and is not a recommended practice; daisy-chaining strips introduces its own hazards and does not replace depleted protective circuitry. Better surge protectors include a status light or audible alarm precisely so technicians know when protection has expired, and any protector that has taken a major surge should be swapped out to keep connected equipment properly guarded against future overvoltage events.
A forensic examiner explains that copying only the visible files from a suspect drive is insufficient for an investigation. Which of the following does a bit-for-bit image capture that an ordinary file copy does NOT?
A bit-for-bit image, also called a bitstream copy or forensic image, duplicates every sector of the storage device exactly, including deleted files that still exist in unallocated space, slack space between the end of a file and the end of its cluster, and file-system metadata, timestamps, and hidden areas. This is precisely what an ordinary file copy misses, because a normal copy grabs only the visible, allocated files. Capturing only the currently allocated and visible user files describes exactly the limitation of a normal OS-level copy, which is why it is inadequate for forensics. Copying just the operating system and installed applications ignores user data, deleted content, and unallocated space where crucial evidence often resides. Capturing solely the file names and folder directory structure records metadata about organization but not the actual data content, deleted material, or slack space. Because so much evidentiary value lies in areas users cannot normally see, forensic analysts always create a complete sector-by-sector image and then verify it with a cryptographic hash to prove it is an exact duplicate.
A field technician is stuck in traffic and realizes they will arrive at a customer's office 30 minutes after the scheduled appointment. Which of the following is the MOST professional action?
Being on time is a stated professionalism expectation, and when you cannot be, the rule is to contact the customer before the appointment time with an honest explanation and a new estimate so they can plan around it. Arriving late and apologizing afterwards leaves the customer waiting and wondering, which is the outcome the rule exists to prevent. Rescheduling without speaking to the customer is worse still, because it wastes the time they had already set aside. Passing the message to a dispatcher may or may not reach the customer promptly; the technician who made the commitment should make the call.
Go deeper
CompTIA A+ practice test FAQ
- How many questions are on the CompTIA A+ exam?
- Each A+ exam has a maximum of 90 questions and a 90-minute time limit. You take two exams: Core 1 (220-1201) and Core 2 (220-1202). Both mix multiple-choice questions with performance-based questions (PBQs).
- What is the passing score for CompTIA A+?
- Scores are scaled from 100 to 900. Core 1 (220-1201) needs 675 / 900; Core 2 (220-1202) needs 700 / 900. You must pass both exams to earn the certification.
- Are these real CompTIA A+ exam questions?
- No. Real exam questions are confidential. These 60 questions are original, written to the official V15 (220-1201/220-1202) objectives to mirror the exam's style and difficulty, each with an explanation of the right and wrong answers.
- Should I take Core 1 or Core 2 first?
- Most candidates take Core 1 first: it covers hardware, networking, mobile devices, and virtualization, and Core 2 (operating systems, security, software troubleshooting, and operational procedures) builds on that foundation. There is no required order.
- Does the CompTIA A+ exam have performance-based questions?
- Yes. Both exams open with a handful of PBQs — interactive tasks such as configuring a router, wiring a PC, or fixing a Windows setting. They are the part most candidates find hardest. You can try free PBQs at examwizardz.app/pbq-practice.
- How long should I study for the A+?
- With an IT background, four to six weeks per exam is typical. Starting from scratch, plan on eight to twelve weeks per exam. Use a practice test like this one early to find weak domains, then drill those sections.
- Is there a longer free A+ practice test?
- Yes. Every Core 1 and Core 2 section has its own free 10-question page (linked below), and a free ExamWizardz account unlocks the first sections of the full course with hundreds more questions, interactive PBQs, and a study plan.
Question set last updated 2026-09-08. CompTIA and A+ are registered trademarks of CompTIA, Inc. ExamWizardz is not affiliated with or endorsed by CompTIA.