[2025年11月最新リリース]220-1102試験問題はあなたをパスさせる
CompTIA 220-1102試験基本問題とアンサー
質問 # 479
A technician needs administrator access on a Windows workstation to facilitate system changes without elevating permissions. Which of the following would best accomplish this task?
- A. System Configuration
- B. Device Manager
- C. Group Policy Editor
- D. Local Users and Groups
正解:D
解説:
Local Users and Groups is the best option to accomplish this task. Local Users and Groups is a tool that allows managing the local user accounts and groups on a Windows workstation. The technician can use this tool to create a new user account with administrator privileges or add an existing user account to the Administrators group. This way, the technician can log in with the administrator account and make system changes without elevating permissions. Group Policy Editor, Device Manager, and System Configuration are not correct answers for this question. Group Policy Editor is a tool that allows configuring policies and settings for users and computers in a domain environment. Device Manager is a tool that allows managing the hardware devices and drivers on a Windows workstation. System Configuration is a tool that allows modifying the startup options and services on a Windows workstation. None of these tools can directly grant administrator access to a user account. Reference:
Official CompTIA learning resources CompTIA A+ Core 1 and Core 2, page 13 CompTIA A+ Complete Study Guide: Core 1 Exam 220-1101 and Core 2 Exam ..., page 103
質問 # 480
A user's iPhone was permanently locked after several failed log-in attempts. Which of the following authentication methods are needed to restore access, applications, and data to the device?
- A. Recovery contact and recovery key
- B. Fingerprint and pattern
- C. Facial recognition and PIN code
- D. Primary account and password
正解:A
解説:
Explanation
If a user's iPhone is permanently locked after several failed log-in attempts, the user will need to use the recovery contact and recovery key to restore access, applications, and data to the device. The recovery contact is a trusted person who can receive a verification code from Apple and share it with the user. The recovery key is a 28-character code that the user created when setting up two-factor authentication for their Apple ID. The user will need to enter both the verification code and the recovery key on another device or computer to unlock their iPhone. This method will erase the iPhone and restore it from the iCloud backup
質問 # 481
A company implemented a BYOD policy and would like to reduce data disclosure caused by malware that may infect these devices. Which of the following should the company deploy to address these concerns?
- A. MDM
- B. UAC
- C. SSO
- D. LDAP
正解:A
解説:
Explanation
MDM stands for mobile device management, which is a type of software solution that allows remote management and security of mobile devices. MDM can help a company reduce data disclosure caused by malware that may infect these devices by enforcing security policies, such as encryption, password protection, antivirus software, and remote wipe. MDM can also monitor and control the access of personal devices to corporate data and networks. UAC stands for user account control, which is a feature of Windows that prompts users for permission or an administrator password before making changes that affect the system. UAC may not be effective in preventing malware infection or data disclosure on personal devices. LDAP stands for lightweight directory access protocol, which is a protocol for accessing and managing information stored in a directory service, such as user names and passwords. LDAP does not directly address the issue of malware infection or data disclosure on personal devices. SSO stands for single sign-on, which is a feature that allows users to access multiple applications or services with one set of credentials. SSO may not prevent malware infection or data disclosure on personal devices, and may even increase the risk if the credentials are compromised.
https://www.nist.gov/news-events/news/2021/03/mobile-device-security-bring-your-own-device-byod-draft-sp-1
質問 # 482
An administrator needs to back up the following components of a single workstation:
* The installation of the operating system
* Applications
* User profiles
* System settings
Which of the following backup methods can the administrator use to ensure the workstation is properly backed up?
- A. Synthetic
- B. Archive
- C. Differential
- D. Image
正解:D
解説:
An image backup captures a complete snapshot of the entire system at a specific point in time, including the operating system, installed applications, user profiles, and system settings. This method is most suitable for backing up the components listed in the question because it ensures that every aspect of the workstation, from the core OS to individual user settings, is preserved and can be restored in its entirety. This is crucial for quickly recovering a system to a fully operational state after a failure or when migrating to new hardware. Other methods like differential, synthetic, and archive backups do not provide the comprehensive one-step restoration capability that an image backup offers for the complete system recovery.
質問 # 483
Which of the following threats will the use of a privacy screen on a computer help prevent?
- A. Whaling
- B. Shoulder surfing
- C. Tailgating
- D. Impersonation
正解:B
解説:
Explanation
Shoulder surfing is a threat that involves someone looking over another person's shoulder to observe their screen, keyboard, or other sensitive information. Shoulder surfing can be used to steal passwords, personal identification numbers (PINs), credit card numbers, or other confidential data. The use of a privacy screen on a computer can help prevent shoulder surfing by limiting the viewing angle of the screen and making it harder for someone to see the screen from the side or behind. Impersonation, whaling, and tailgating are not threats that can be prevented by using a privacy screen on a computer.
質問 # 484
Ann, a CEO, has purchased a new consumer-class tablet for personal use, but she is unable to connect it to the company's wireless network. All the corporate laptops are connecting without issue. She has asked you to assist with getting the device online.
INSTRUCTIONS
Review the network diagrams and device configurations to determine the cause of the problem and resolve any discovered issues.
If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.








正解:
解説:
See the Explanation below:
Explanation:
Click on 802.11 and Select ac
Click on SSID and select CORP
Click on Frequency and select 5GHz
At Wireless Security Mode, Click on Security Mode
Select the WPA2
Ann needs to connect to the BYOD SSID, using 2.4GHZ. The selected security method chose should be WPA PSK, and the password should be set to TotallySecret.
質問 # 485
Which of the following is an advantage of using WPA2 instead of WPA3?
- A. Offline decryption resistance
- B. Connection security
- C. Device compatibility
- D. Encryption key length
正解:C
解説:
Device compatibility is an advantage of using WPA2 instead of WPA3. WPA2 is the previous version of the Wi-Fi Protected Access protocol, which provides security and encryption for wireless networks. WPA3 is the latest version, which offers improved security features, such as stronger encryption, enhanced protection against brute-force attacks, and easier configuration. However, WPA3 is not backward compatible with older devices that only support WPA2 or earlier protocols. Therefore, using WPA3 may limit the range of devices that can connect to the wireless network. Connection security, encryption key length, and offline decryption resistance are advantages of using WPA3 instead of WPA2. References:
Official CompTIA learning resources CompTIAA+ Core 1 and Core 2, page 24 CompTIA A+ Certification All-in-One Exam Guide (Exams 220-1101 & ..., page 1000
質問 # 486
A technician is troubleshooting a mobile device that was dropped. The technician finds that the screen (ails to rotate, even though the settings are correctly applied. Which of the following pieces of hardware should the technician replace to resolve the issue?
- A. Digitizer
- B. LCD
- C. Battery
- D. Accelerometer
正解:D
解説:
Explanation
The piece of hardware that the technician should replace to resolve the issue of the screen failing to rotate on a mobile device that was dropped is the accelerometer. The accelerometer is a sensor that detects the orientation and movement of the mobile device by measuring the acceleration forces acting on it. The accelerometer allows the screen to rotate automatically according to the position and angle of the device. If the accelerometer is damaged or malfunctioning, the screen may not rotate properly or at all, even if the settings are correctly applied. LCD stands for Liquid Crystal Display and is a type of display that uses liquid crystals and backlight to produce images on the screen. LCD is not related to the screen rotation feature but to the quality and brightness of the display. Battery is a component that provides power to the mobile device by storing and releasing electrical energy. Battery is not related to the screen rotation feature but to the battery life and performance of the device. Digitizer is a component that converts touch inputs into digital signals that can be processed by the mobile device. Digitizer is not related to the screen rotation feature but to the touch sensitivity and accuracy of the display. References: CompTIA A+ Core 2 (220-1002) Certification Exam Objectives Version 4.0, Domain 1.5
質問 # 487
A user is trying to use a third-party USB adapter but is experiencing connection issues. Which of the following tools should the technician use to resolve this issue?
- A. eventvwr.msc
- B. taskschd.msc
- C. diskmgmt.msc
- D. de vmgmt. msc
正解:D
解説:
Explanation
The tool that the technician should use to resolve the connection issues with the third-party USB adapter is devmgmt.msc. Devmgmt.msc is a command that opens the Device Manager, which is a utility that allows users to view and manage the hardware devices and drivers installed on a computer. The technician can use the Device Manager to check the status, properties and compatibility of the USB adapter and its driver, and perform actions such as updating, uninstalling or reinstalling the driver, enabling or disabling the device, or scanning for hardware changes. Taskschd.msc is a command that opens the Task Scheduler, which is a utility that allows users to create and manage tasks that run automatically at specified times or events. The Task Scheduler is not relevant or useful for resolving connection issues with the USB adapter. Eventvwr.msc is a command that opens the Event Viewer, which is a utility that allows users to view and monitor the system logs and events. The Event Viewer may provide some information or clues about the connection issues with the USB adapter, but it does not allow users to manage or troubleshoot the device or its driver directly.
Diskmgmt.msc is a command that opens the Disk Management, which is a utility that allows users to view and manage the disk drives and partitions on a computer. The Disk Management is not relevant or useful for resolving connection issues with the USB adapter. References: CompTIA A+ Core 2 (220-1002) Certification Exam Objectives Version 4.0, Domain 1.6
質問 # 488
A technician is setting up a newly built computer. Which of the following is the fastest way for the technician to install Windows 10?
- A. System Restore
- B. Unattended installation
- C. In-place upgrade
- D. Factory reset
正解:B
解説:
Windows 10
The correct answer is D. Unattended installation. An unattended installation is a way of installing Windows 10 without requiring any user input or interaction. It uses a configuration file called answer file that contains the settings and preferences for the installation, such as the product key, language, partition, and network settings.An unattended installation can be performed by using a bootable USB flash drive or DVD that contains the Windows 10 installation files and the answer file1. This is the fastestway for the technician to install Windows 10 on a newly built computer, as it automates the whole process and saves time.
A factory reset is a way of restoring a computer to its original state by deleting all the data and applications and reinstalling the operating system.A factory reset can be performed by using the recovery partitionor media that came with the computer, or by using the Reset this PC option in Windows 10 settings2. A factory reset is not a way of installing Windows 10 on a newly built computer, as it requires an existing operating system to be present.
A system restore is a way of undoing changes to a computer's system files and settings by using a restore point that was created earlier.A system restore can be performed by using the System Restore option in Windows 10 settings or by using the Advanced Startup Options menu3. A system restore is not a way of installing Windows 10 on a newly built computer, as it requires an existing operating system and restore points to be present.
An in-place upgrade is a way of upgrading an existing operating system to a newer version without losing any data or applications. An in-place upgrade can be performed by using the Windows 10 Media Creation Tool or by running the Setup.exe file from the Windows 10 installation media. An in-place upgrade is not a way of installing Windows 10 on a newly built computer, as it requires an existing operating system to be present.
質問 # 489
A technician receives an invalid certificate error when visiting a website. Other workstations on the same local network are unable to replicate this issue. Which of the following is most likely causing the issue?
- A. User access control
- B. UEFI boot mode
- C. Date and time
- D. Log-on times
正解:C
解説:
Date and time is the most likely cause of the issue. The date and time settings on a workstation affect the validity of the certificates used by websites to establish secure connections. If the date and time are incorrect, the workstation may not recognize the certificate as valid and display an invalid certificate error. Other workstations on the same local network may not have this issue if their date and time are correct. User access control, UEFI boot mode, and log-on times are not likely causes of the issue. User access control is a feature that prevents unauthorized changes to the system by prompting for confirmation or credentials. UEFI boot mode is a firmware interface that controls the boot process of the workstation. Log-on times are settings that restrict when a user can log in to the workstation. None of these factors affect the validity of the certificates used by websites. References:
* Official CompTIA learning resources CompTIA A+ Core 1 and Core 2, page 14
* CompTIA A+ Core 1 (220-1101) and Core 2 (220-1102) Cert Guide, page 456
質問 # 490
During Windows updates, a technician receives an error message stating, "The process is currently disabled." Assuming the event is not malicious, which of the following is the best command for the technician to use to re-enable Windows updates?
- A. certmgr.msc
- B. psr.exe
- C. services.msc
- D. wf.msc
- E. msconfig.exe
正解:C
解説:
Comprehensive and Detailed In-Depth Explanation:
The services.msc command opens the Services management console in Windows, which allows users to start, stop, and configure the settings of system services. Windows Update operates as a service named "Windows Update" or "wuauserv." If this service is disabled, Windows updates cannot proceed. By accessing services.
msc, a technician can locate the Windows Update service and set its startup type to "Automatic" or manually start the service, thereby resolving the issue.
* Option A: wf.mscThis command opens the Windows Firewall with Advanced Security console, used for configuring firewall rules. It doesn't manage services.
* Option C: msconfig.exeThis System Configuration utility allows users to configure startup options and services but is not specifically designed for managing individual services like Windows Update.
* Option D: certmgr.mscThis command opens the Certificate Manager, which manages digital certificates. It doesn't control system services.
* Option E: psr.exeThe Problem Steps Recorder is a tool that records user actions to help with troubleshooting but doesn't manage services.
Reference: CompTIA A+ Core 2 (220-1102) Exam Objectives, Domain 1.5: "Given a scenario, use Microsoft operating system tools."
質問 # 491
Which of the following common security vulnerabilities can be mitigated by using input validation?
- A. Cross-site request forgery
- B. SQL injection
- C. Brute-force attack
- D. Cross-site scripting
正解:B、D
解説:
Cross-site scripting (XSS) and SQL injection are common security vulnerabilities that can be mitigated by using input validation. Input validation is a technique that checks the user input for any malicious or unexpected characters or commands before processing it. XSS is an attack that injects malicious scripts into web pages to steal cookies, session tokens or other sensitive information from users or web servers. SQL injection is an attack that injects malicious SQL statements into web applications to manipulate databases, execute commands or access unauthorized data. Verified References: https://www.comptia.org/blog/what-is- input-validation https://www.comptia.org/certifications/a
質問 # 492
A user's iPhone was permanently locked after several tailed login attempts. Which of the following will restore access to the device?
- A. Fingerprint and pattern
- B. Facial recognition and PIN code
- C. Secondary account and recovery code
- D. Primary account and password
正解:C
解説:
A secondary account and recovery code are used to reset the primary account and password on an iPhone after it has been locked due to failed login attempts. Fingerprint, pattern, facial recognition and PIN code are biometric or numeric methods that can be used to unlock an iPhone, but they are not helpful if the device has been permanently locked. Verified References: https://support.apple.com/en-us/HT204306 https://www.
comptia.org/certifications/a
質問 # 493
Which of the following is the most significant drawback of using the WEP protocol for wireless security?
- A. Slow data transfer speed
- B. Incompatibility with older devices
- C. Complex configuration process
- D. Vulnerability to key-cracking attacks
正解:D
解説:
Comprehensive and Detailed In-Depth Explanation:WEP (Wired Equivalent Privacy) is highly vulnerable to key-cracking attacks, as its encryption key can be easily broken with freely available tools.
* A. Complex configuration process - Incorrect. WEP is actually easy to configure.
* B. Slow data transfer speed - Incorrect. WEP does not significantly impact speed.
* D. Incompatibility with older devices - Incorrect. WEP is compatible with older devices but is insecure.
Reference:
CompTIA A+ 220-1102, Objective 2.6 - Wireless Security Protocols
質問 # 494
A technician is troubleshooting a PC that is unable to perform DNS lookups. Utilizing the following firewall output:
Protocol/Port Action Direction
1 Allow Out
445 Block Out
53 Block Out
123 Block Out
80 Block Out
Which of the following ports should be opened to allow for DNS recursion?
- A. 0
- B. 1
- C. 2
- D. 3
- E. 4
正解:C
解説:
DNS (Domain Name System) lookups are essential for translating human-friendly domain names into IP addresses that computers use to communicate. DNS typically uses port 53 for its communication.
In the provided firewall output, various ports are either allowed or blocked for outgoing traffic. For DNS recursion, which is the process of resolving domain names to IP addresses, port 53 must be open.
Port 53: This is the standard port used by DNS for queries and responses. The fact that it is currently blocked (as per the firewall output) is the reason why DNS lookups are failing. Opening port 53 will allow the DNS requests to pass through the firewall, enabling the resolution of domain names to IP addresses.
Other ports mentioned in the output are used for different services and protocols:
Port 1 is generally not used for standard services.
Port 445 is associated with SMB (Server Message Block) for file sharing in Windows environments.
Port 123 is used by NTP (Network Time Protocol) for time synchronization.
Port 80 is used for HTTP traffic, which is web traffic but not related to DNS lookups.
質問 # 495
A customer service representative is unable to send jobs to a printer at a remote branch office. However, the representative can print successfully to a local network printer. Which of the following commands should a technician use to view the path of the network traffic from the PC?
- A. ping
- B. netstat
- C. format
- D. tracert
正解:D
解説:
The "tracert" command is used to view the path that network traffic takes from a PC to a specified destination.
It is helpful in identifying where along the path the traffic may be failing or experiencing delays. In the scenario where a customer service representative can't send jobs to a remote printer but can print locally,
"tracert" can help diagnose if there's a network routing issue affecting the connection to the remote branch office.
質問 # 496
A user reports a PC is running slowly. The technician suspects it has a badly fragmented hard drive. Which of the following tools should the technician use?
- A. msmfo32.exe
- B. dfrgui exe
- C. msconfig.extf
- D. resmon exe
正解:B
解説:
The technician should use dfrgui.exe to defragment the hard drive1
質問 # 497
A technician is troubleshooting a Windows system that is having issues with the OS loading at startup. Which of the following should the technician do to diagnose the issue?
- A. Launch the last known-good configuration.
- B. Check the system resource usage in Task Manager.
- C. Run the sfc /scannow command.
- D. Enable boot logging on the system.
- E. Use the Event Viewer to open the application log
正解:D
解説:
When troubleshooting a Windows system that is experiencing issues during the OS loading phase at startup, enabling boot logging is a practical step. Boot logging creates a record of all drivers and services that are loaded (or attempted to be loaded) during the startup process. This record, typically named ntbtlog.txt, can be reviewed to identify any drivers or services that failed to load, which could be contributing to the startup issues. This diagnostic step helps pinpoint the problematic component(s) and facilitates targeted troubleshooting to resolve the OS loading issues.
質問 # 498
A systems administrator is creating periodic backups of a folder on a Microsoft Windows machine. The source data is very dynamic, and files are either added or deleted regularly. Which of the following utilities can be used to 'mirror the source data for the backup?
- A. xcopy
- B. copy
- C. robocopy
- D. Copy-Item
正解:C
解説:
Robocopy is a command-line utility that can be used to mirror the source data for the backup. It can copy files and folders with various options, such as copying only changed files, preserving attributes and permissions, and retrying failed copies. Robocopy is more powerful and flexible than copy or xcopy, which are simpler commands that can only copy files and folders without mirroring or other advanced features. Copy-Item is a PowerShell cmdlet that can also copy files and folders, but it is not a native Windows utility and it requires PowerShell to run1.
References: 1: https://windowsreport.com/mirror-backup-software/
質問 # 499
A neighbor successfully connected to a user's Wi-Fi network. Which of the following should the user do after changing the network configuration to prevent the neighbor from being able to connect again?
- A. Disable encryption settings.
- B. Disable the SSID broadcast.
- C. Disable logging.
- D. Disable DHCP reservations.
正解:B
解説:
The SSID broadcast is a feature that allows a Wi-Fi network to be visible to nearby devices. Disabling the SSID broadcast can make the network harder to find by unauthorized users, but it does not prevent them from accessing it if they know the network name and password.
質問 # 500
A department manager submits a help desk ticket to request the migration of a printer's port utilization from USB to Ethernet so multiple users can access the printer. This will be a new network printer, thus a new IP address allocation is required. Which of the following should happen immediately before network use is authorized?
* Document the date and time of the change.
- A. Request an unused IP address.
- B. Determine the risk level of this change.
- C. Submit a change request form.
正解:B
解説:
A change request form is a document that describes the proposed change, the reason for the change, the impact of the change, and the approval process for the change. A change request form is required for any planned changes to the network, such as adding a new network printer, to ensure that the change is authorized, documented, and communicated to all stakeholders. Submitting a change request form should happen immediately before network use is authorized, as stated in the Official CompTIA A+ Core 2 Study Guide.
The other options are either too late (documenting the date and time of the change) or too early (determining the risk level of the change and requesting an unused IP address) in the change management process.
質問 # 501
......
2025年最新のリアルな無料CompTIA 220-1102試験問題集問題と解答:https://www.jpntest.com/shiken/220-1102-mondaishu
220-1102練習テストエンジン購入前に試そう836試験問題:https://drive.google.com/open?id=18hQsl0qJORZAsC5ACaCHr6mqGTlO7Joc