Get 2026 Free CompTIA 220-1202 Exam Practice Materials Collection [Q109-Q127]

Share

Get 2026 Free CompTIA 220-1202 Exam Practice Materials Collection

Get Latest and 100% Accurate 220-1202 Exam Questions

NEW QUESTION # 109
An organization sees unauthorized apps installed and licensing prompts. What should the security team do?

  • A. Deploy an internal PKI to filter encrypted web traffic.
  • B. Implement stronger controls to block suspicious websites.
  • C. Remove users from the local admin group.
  • D. Enable stricter UAC settings on Windows.

Answer: C

Explanation:
Removing users from thelocal admin groupprevents them from installing unauthorized software.
FromQuentin Docter - Complete Study Guide:
"Local admin privileges allow users to install unauthorized apps. Removing them from this group restricts installations and helps prevent malware." .


NEW QUESTION # 110
Users are reporting that an unsecured network is broadcasting with the same name as the normal wireless network. They are able to access the internet but cannot connect to the file share servers. Which of the following best describes this issue?

  • A. Unreachable DNS server
  • B. Virtual local area network misconfiguration
  • C. Incorrect IP address
  • D. Rogue wireless access point

Answer: D

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
This scenario describes a rogue access point - a malicious or unauthorized wireless access point that uses the same SSID as the legitimate network. Users may connect to it unknowingly, which can result in limited network access, data interception, or redirection of traffic. The inability to reach internal file servers supports this being an unauthorized AP with no connection to internal resources.
A: A DNS issue would impact name resolution, not connectivity to file servers directly.
B: VLAN issues generally affect segmentation, not mimic SSID problems.
C: An incorrect IP address could cause connectivity issues, but not in the presence of a malicious AP broadcasting the same SSID.
Reference:
CompTIA A+ 220-1102 Objective 2.4: Compare and contrast wireless and physical security threats.
Study Guide Section: Rogue access points and their detection


NEW QUESTION # 111
A technician is tasked with disposing of several hard drives from a government client that contains highly confidential data. The client requires documented proof of destruction to ensure regulatory compliance. Which of the following is the BEST method for the technician to use?

  • A. Certified third-party destruction
  • B. Targeted file deletion
  • C. Low-level formatting
  • D. In-house disk incineration

Answer: A

Explanation:
Because this is a government client with confidential data and a strict requirement to follow regulatory compliance , the best practice is to use a certified third-party destruction service that can provide documented proof of destruction. The All-in-One guide explicitly notes that "professional hard drive disposal services are third-party vendors" that guarantee drives are thoroughly destroyed by issuing a certificate of destruction
/recycling , which provides assurance that data will not fall into the wrong hands. Mike Meyers' Lab Manual repeats the same exam point: third-party vendors "will guarantee they have truly, thoroughly destroyed drives by issuing a certificate of destruction/recycling." Low-level formatting (often used to mean overwrite/zero-fill) can sanitize drives, but it may not satisfy the requirement for provable compliance and chain-of-custody documentation, especially for regulated environments. Targeted deletion is ineffective because deleted data can remain recoverable. In-house incineration is extreme and may be restricted, unsafe, or noncompliant without proper facilities and documentation. Therefore, Certified third-party destruction (B) is the best option.


NEW QUESTION # 112
A user downloads an application with a plug-in that is designed to automatically prompt for an OTP when the user browses to a specific website. The plug-in installs without any warnings or errors. The first time the user goes to the site, the prompt does not open, and the user cannot access the site. Which of the following browser settings should the user configure?

  • A. Extensions/add-ins
  • B. Proxy settings
  • C. Trusted sources
  • D. Certificate validity

Answer:

Explanation:
The user should configure extensions/add-ins settings because the plug-in (extension) may be disabled or blocked, preventing it from prompting for the OTP as intended.


NEW QUESTION # 113
A user is attempting to install a specialized software application on a macOS workstation. When the user double-clicks the installer, an error message appears stating that the application cannot be opened because it is from an unidentified developer. In which of the following System Preferences (or System Settings) panes can a technician modify the settings to allow this application to run?

  • A. Accessibility
  • B. iCloud (corrected from "iCIoud")
  • C. Finder
  • D. Privacy

Answer: D

Explanation:
This is macOS "Gatekeeper"-style behavior: the OS warns when an app is not from a trusted source (for example, not signed/not from an identified developer). In Quentin Docter's macOS section, the correct place to control what apps are allowed is Security & Privacy . He states that in Security & Privacy, "the applications downloaded on the device can also be controlled; you can select whether apps can be downloaded only from the App Store or from App Store And Identified Developers, which is the default." He also notes many advanced settings in Security & Privacy require unlocking with an administrator password.
Although the exact control is on the General area of Security & Privacy (not the Privacy tab itself), among the answer choices the closest and intended match is Privacy (A) because it points to the correct macOS security settings area in System Preferences/System Settings. Accessibility and Finder do not manage app trust controls, and iCloud relates to syncing/account services rather than software signing enforcement.


NEW QUESTION # 114
The Chief Information Officer (CIO) is overseeing a project to integrate existing business processes to an enterprise resource planning system. The CIO identifies the scope of the change and provides it to the IT department. Which of the following is the first change management procedure to perform before measuring the impact to the systems?

  • A. Document findings
  • B. Backup plan
  • C. Risk analysis
  • D. Sandbox testing

Answer: D

Explanation:
Before you can accurately understand impact (what will break, what will change, what dependencies exist), you should validate the change in a controlled environment. Mike Meyers' Lab Manual defines sandbox testing as using a safe place "where you can experiment without messing up the primary system," typically a virtualized environment that isolates the test machine and enables restore from snapshots. It states sandbox testing "entails checking out new and updated applications without putting the systems and data you depend on at risk." The All-in-One guide mirrors this exact best practice for change management, emphasizing that you don't roll changes into production for many users/systems without "thorough testing and analysis," and highlights sandbox testing as a documented business process used to evaluate changes safely. In this scenario, the scope is known, so the next "first" practical procedure to evaluate effect is to test it in a sandbox so you can then measure and document impacts based on evidence. A rollback/backup plan is critical, but sandbox testing comes first to determine what safeguards are required.


NEW QUESTION # 115
A help desk technician is setting up speech recognition on a Windows system. Which of the following settings should the technician use?

  • A. Ease of Access
  • B. Time and Language
  • C. System
  • D. Personalization

Answer: A


NEW QUESTION # 116
A technician is 3-D printing high-strength, carbon fiber-based filament parts for a customer order. Which of the following is the most important for the technician to use?

  • A. ESD mat
  • B. Steel-toed boots
  • C. Air filter mask
  • D. Antistatic bags

Answer: C

Explanation:
Carbon fiber filamentcan producefine particles or fumesduring printing, which may be harmful when inhaled.
Wearing anair filter maskis essential to protect the respiratory system.
FromQuentin Docter - CompTIA A+ Complete Study Guide:
"When working with advanced materials like carbon fiber, always use appropriate personal protective equipment such as air filter masks to prevent inhalation of dangerous particles."


NEW QUESTION # 117
Which of the following tools should a technician use in macOS to restore an older version of a file?

  • A. Disk Utility
  • B. FileVault
  • C. Time Machine
  • D. Spotlight

Answer: C

Explanation:
Time Machine is the macOS backup and recovery tool used to restore older versions of files or recover deleted data.


NEW QUESTION # 118
A user receives an unexpected text message containing a link to reset an expired password. Which of the following social engineering attacks is taking place?

  • A. Spear phishing
  • B. Whaling
  • C. Smishing
  • D. Vishing

Answer: C

Explanation:
The correct answer is D. Smishing, which is a form of phishing attack conducted via SMS text messages.
The key indicators in this scenario are the unexpected text message and the embedded link prompting the user to reset a password. These attacks rely on urgency and fear to trick users into clicking malicious links or providing credentials.
According to the Quentin Docter - CompTIA A+ Complete Study Guide, smishing attacks often impersonate legitimate organizations such as banks, IT departments, or service providers. The attacker claims that an account action is required, such as resetting an expired password, to prompt immediate user response.
The Travis Everett & Andrew Hutz - All-in-One Exam Guide explains that smishing is distinct from other phishing variants based on delivery method. Vishing uses voice calls, spear phishing targets specific individuals via email, and whaling targets high-level executives. Since this attack is delivered via text message, it is classified as smishing.
The Mike Meyers / Mark Soper Lab Manual reinforces that modern attackers increasingly use SMS because users often trust text messages more than emails. This makes smishing a highly effective and common attack vector.
Because the attack uses SMS with a malicious link, smishing is the correct answer.


NEW QUESTION # 119
A user reports that the time on their computer does not match the time on their VoIP phone.
Which of the following should a technician do to fix the time difference?

  • A. Confirm the user is logging in to the domain
  • B. Download and install the latest BIOS update
  • C. Configure access to an available NTP server
  • D. Manually set the time on the phone to match the computer

Answer: C

Explanation:
Configuring access to an available Network Time Protocol server ensures both the computer and the VoIP phone synchronize their clocks to the same authoritative time source, resolving time discrepancies automatically.


NEW QUESTION # 120
Which of the following describes an attack in which an attacker sets up a rogue AP that tricks users into connecting to the rogue AP instead of the legitimate network?

  • A. Shoulder surfing
  • B. Evil twin
  • C. Stalkerware
  • D. Tailgating

Answer: B

Explanation:
An evil twin is a rogue wireless access point set up to mimic a legitimate Wi-Fi network. Unsuspecting users may connect to it, giving attackers the opportunity to intercept traffic, steal credentials, or install malware.
The evil twin often uses the same SSID as the real network to fool users.
A). Stalkerware is spyware installed to track user activity, typically on personal devices.
C). Tailgating is a physical security breach involving unauthorized entry behind someone with access.
D). Shoulder surfing involves observing a person entering confidential data, such as PINs or passwords.
Reference:
CompTIA A+ 220-1102 Objective 2.3: Compare and contrast social engineering and wireless attacks.
Study Guide Section: Wireless threats - rogue APs and evil twin scenarios


NEW QUESTION # 121
Welcome to your first day as a Fictional Company, LLC helpdesk employee. Please work the tickets in your helpdesk ticket queue.
INSTRUCTIONS
Click on individual tickets to see the ticket details, and view applicable attachments to determine the problem.
Select the appropriate issue from the 'Issue' drop-down menu. Then, select the most efficient resolution from the 'Resolution' drop-down menu. Finally, select the proper command or verification to remediate or confirm your fix of the issue from the
'Verify/Resolve' drop-down menu.

Answer:

Explanation:

Explanation:
Ticket #8675310
* Issue: Limited network connectivity
* Resolution: Refresh DHCP
* Verify/Resolve: ipconfig /renew
For the Low priority ticket #8675310 ("A small yellow triangle appeared in the taskbar. I am no longer able to access network resources."), the Windows yellow triangle on the network icon is the classic indicator of limited connectivity (often caused by a bad/expired DHCP lease, APIPA address, missing default gateway, or DNS info not being assigned).
Correct PBQ Selections (Ticket #8675310)
Issue
Limited network connectivity
Why (CompTIA logic):
That yellow warning triangle means the NIC is connected at Layer 2 (link is up), but the system likely doesn't have valid Layer 3 config (IP/gateway/DNS), so it can't reach network resources.
Resolution
Refresh DHCP
Why this is the most efficient fix:
When a Windows PC can't access network resources and shows "limited connectivity," the fastest, lowest- risk fix is to renew DHCP so the PC can pull:
* a valid IP address
* default gateway
* DNS servers
This directly resolves the most common root cause behind that icon.
Verify / Resolve
ipconfig /renew
Why this is the correct verification/remediation command:
ipconfig /renew is the direct command to request a fresh DHCP lease. After renewal, the user should regain access to network resources if DHCP was the issue.
What this fixes (what you'd expect to see)
Before the fix, the attachment (Output.txt) in these PBQs typically shows symptoms like:
* 169.254.x.x (APIPA) # DHCP failed
* Missing/blank Default Gateway
* DNS not present or incorrect
After ipconfig /renew, you should see a normal private IP (like 192.168.x.x / 10.x.x.x / 172.16-31.x.x) and a valid gateway/DNS.


NEW QUESTION # 122
A technician is troubleshooting an application issue and needs to access a log file located in the C:\Users\<username>\AppData\Local directory. However, when the technician navigates to the user's profile folder, the AppData folder is not visible. Which of the following Control Panel utilities should the technician use to make this folder appear?

  • A. Privacy
  • B. Ease of Access
  • C. Indexing
  • D. File Explorer Options

Answer: D

Explanation:
The AppData folder is located inside a user profile (for example, C:\Users\ < username > \AppData ) and is hidden by default in Windows, so users often can't browse to it unless hidden items are displayed. The correct way to make the folder visible and easy to navigate is to adjust File Explorer Options (Folder Options). Mike Meyers' Lab Manual explains that the View tab in Folder Options provides Advanced settings where you can
" Show hidden files, folders, and drives " because "File Explorer hides them by default." That directly enables AppData visibility in normal navigation.
The All-in-One guide provides the same workflow: accessing File Explorer Options opens a dialog where the
"View options" include the setting to "Show hidden files, folders, and drives," and it notes hidden extensions and other view behaviors are managed here as well.
Indexing affects search performance, not visibility. Privacy and Ease of Access don't control hidden folder display. Therefore, configure File Explorer Options (B).


NEW QUESTION # 123
A user is unable to access an external vendor website from the corporate network. Which of the following Windows command-line tools should a technician use to determine where the issue is potentially occurring?

  • A. ipconfig
  • B. nslookup
  • C. tracert
  • D. ping

Answer: C

Explanation:
The tracert command traces the route packets take to reach a destination and displays each hop along the path. This allows the technician to identify where communication is failing between the corporate network and the external vendor website.


NEW QUESTION # 124
Performance on a user's smartphone is degrading. Applications take a long time to start, and switching between apps is slow. Which of the following diagnostic steps should a mobile technician take first?

  • A. Check the phone's battery state
  • B. Restore the phone to factory settings
  • C. Uninstall unneeded applications
  • D. Restart the phone

Answer: C

Explanation:
Comprehensive and Detailed Explanation From Exact Extract:
One of the most common causes for performance degradation on smartphones isstorage or memory overloaddue to excessive apps.Uninstalling unused appsis a basic but effective first diagnostic step.
FromTravis Everett - All-in-One Exam Guide:
"Start troubleshooting sluggish smartphones by clearing unused apps and files before performing advanced diagnostics or resets."


NEW QUESTION # 125
An administrator applies security controls to a workstation that will provide protection from a brute-force attack against the user account. Which of the following actions should the administrator take?

  • A. Lock the account after three failed attempts.
  • B. Restrict login times to the users' working hours.
  • C. Force login when waking up the workstation.
  • D. Implement least privilege principles on the computer.

Answer: A

Explanation:
The correct answer is C. Lock the account after three failed attempts. A brute-force attack attempts many password guesses. Account lockout directly slows or stops this by preventing unlimited login attempts. Quentin Docter's Complete Study Guide explains that administrators should configure user account settings to limit the number of failed login attempts before the account is locked for a period of time. It specifically notes that setting a failed login attempt counter and lockout duration slows the progress of password attacks. The same material notes that three failed attempts provides better security, although it may create more help desk calls.
Restricting login times may reduce the attack window but does not stop repeated guessing during allowed hours. Requiring login after wake protects unattended sessions. Least privilege limits damage after compromise, but account lockout best mitigates brute-force password attempts.


NEW QUESTION # 126
Which of the following methods involves requesting a user's approval via a push notification to verify the user's identity?

  • A. Hardware token
  • B. SMS
  • C. Call
  • D. Authenticator

Answer: D

Explanation:
Authenticator apps, such as Google Authenticator or Microsoft Authenticator, can be configured to sendpush notificationsto users for approval when logging in. This is a form of multi-factor authentication.
FromAll-in-One Exam Guide:
"Push-based two-factor authentication uses an authenticator app to send a notification to a mobile device. The user must approve the login attempt in real time, ensuring the request is valid."


NEW QUESTION # 127
......

Maximum Grades By Making ready With 220-1202 Dumps: https://lead2pass.prep4sureexam.com/220-1202-dumps-torrent.html