220-1002 Sample Questions

220-1002 Sample Questions & Answers

Free A+ Certification Exam: Core 2 practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.

Launch the full 220-1002 simulator →

Showing 9 of 19 free samples.

  1. Question 1Select 2

    A small office’s wireless network was compromised recently by an attacker who brute forced a PIN to gain access. The attacker then modified the DNS settings on the router and spread malware to the entire network.
    Which of the following configurations MOST likely allowed the attack to take place? (Choose two.)

    Show answer & explanation

    Correct answers: C, F

    The attack described indicates WPS (Wi-Fi Protected Setup) and WEP vulnerabilities were exploited. WPS uses an 8-digit PIN that can be brute-forced relatively easily, especially since the last digit is a checksum, leaving only 7 digits to crack. Once WPS is compromised, attackers gain full network access. WEP encryption is also notoriously weak and easily cracked. Default login credentials on the router allowed DNS modification after network access was gained. Guest networks, TKIP, and outdated firmware, while security concerns, were not the primary attack vectors described in this scenario.

    The attack described indicates WPS (Wi-Fi Protected Setup) and WEP vulnerabilities were exploited. WPS uses an 8-digit PIN that can be brute-forced relatively easily, especially since the last digit is a checksum, leaving only 7 digits to crack. Once WPS is compromised, attackers gain full network access. WEP encryption is also notoriously weak and easily cracked. Default login credentials on the router allowed DNS modification after network access was gained. Guest networks, TKIP, and outdated firmware, while security concerns, were not the primary attack vectors described in this scenario.

  2. Question 2

    A client wants a technician to create a PC naming convention that will make the client’s PCs easier to track and identify while in use.
    Which of the following naming convention formats should the technician follow?

    Show answer & explanation

    Correct answer: C

    Asset ID and MAC address provide the most effective PC naming convention for tracking and identification. Asset IDs are unique organizational identifiers that link directly to inventory management systems for asset tracking, warranty management, and support records. MAC addresses are globally unique hardware identifiers that never change, making devices easily identifiable on networks. Domain names and locations can change, IP addresses are dynamic and reassignable, and RFID requires additional hardware infrastructure that may not be present in all environments.

  3. Question 3Select 2

    Which of the following provide the BEST security for a server room? (Choose two.)

    Show answer & explanation

    Correct answers: A, C

    Badge readers and biometric locks provide the best security for server rooms by implementing multi-factor authentication and access control. Badge readers validate authorized personnel through ID cards linked to access control systems, providing audit trails of entry/exit times. Biometric locks use unique physical characteristics like fingerprints or retinal scans that cannot be duplicated or shared, ensuring only authorized individuals gain access. Bollards protect against vehicle intrusion but not relevant for server rooms, cable locks secure individual devices but not room access, USB tokens are authentication devices but not access control systems, and privacy window shades provide visual security but no access control.

    Badge readers and biometric locks provide the best security for server rooms by implementing multi-factor authentication and access control. Badge readers validate authorized personnel through ID cards linked to access control systems, providing audit trails of entry/exit times. Biometric locks use unique physical characteristics like fingerprints or retinal scans that cannot be duplicated or shared, ensuring only authorized individuals gain access. Bollards protect against vehicle intrusion but not relevant for server rooms, cable locks secure individual devices but not room access, USB tokens are authentication devices but not access control systems, and privacy window shades provide visual security but no access control.

  4. Question 4

    Which of the following threats uses personalized information in an attempt at obtaining information?

    Show answer & explanation

    Correct answer: D

    Spear phishing uses personalized information to target specific individuals with customized attacks that appear legitimate. Unlike generic phishing, spear phishing incorporates personal details like names, job titles, company information, or recent activities to increase credibility and success rates. Whaling targets high-profile executives but is not necessarily personalized, impersonation involves pretending to be someone else but may not use personal information, and spoofing involves falsifying sender information but does not necessarily incorporate personalized content about the target.

  5. Question 5

    A technician receives an invalid certificate error when visiting a website with port 443 enabled. Other computers on the same LAN do not exhibit this symptom.
    Which of the following needs to be adjusted on the workstation to fix the issue?

    Show answer & explanation

    Correct answer: A

    Invalid certificate errors on port 443 (HTTPS) affecting only one workstation typically indicate incorrect date and time settings. SSL/TLS certificates have validity periods defined by start and end dates, and browsers reject certificates if the local system time falls outside this range. Since other computers on the same LAN work properly, the issue is isolated to this specific workstation system configuration. UEFI boot mode affects hardware initialization not certificate validation, logon times control user access periods not certificate verification, and user access control manages permissions but does not affect certificate date validation.

  6. Question 6

    A department in an organization set up a proxy server to manage its Internet stage. A technician is configuring the Windows workstations to use the new proxy server.
    Which of the following Control Panel utilities should the technician use to configure the setting?

    Show answer & explanation

    Correct answer: B

    Internet Options - Connections is the correct Control Panel utility for configuring proxy server settings in Windows workstations. The Connections tab contains the LAN Settings button which opens the Local Area Network (LAN) Settings dialog where proxy server configuration is managed, including server address, port, and bypass settings. The Advanced tab handles security protocols and encryption, Security tab manages zone settings and permissions, Content tab controls certificates and autocomplete, and Privacy tab manages cookies and pop-up blocking, none of which are used for proxy server configuration.

  7. Question 7

    Which of the following is the amount of memory a user is limited to with a 32-bit version of Windows?

    Show answer & explanation

    Correct answer: B

    32-bit versions of Windows are limited to 4GB of addressable memory due to the architectural constraints of 32-bit processing. A 32-bit system can address 2^32 memory locations, which equals 4,294,967,296 bytes or exactly 4GB. While some 32-bit versions of Windows can access slightly more than 4GB through Physical Address Extension (PAE), the practical user-accessible limit remains 4GB. 64-bit Windows versions can address significantly more memory, but 32-bit systems are fundamentally constrained by their bit architecture to 4GB maximum addressable space.

  8. Question 8

    A technician is working at a help desk firm and receives a call from a user who has experienced repeated BSODs. The technician is scheduled to take a break just after the call comes in.
    Which of the following is the BEST choice for the technician to make?

    Show answer & explanation

    Correct answer: B

    Asking another technician to take the call demonstrates proper customer service and ensures continuous support coverage. Repeated BSODs indicate serious system instability requiring immediate attention, and customer service standards prioritize helping users without delay. Asking the user to call back provides poor customer experience, troubleshooting while rushed before a break may lead to incomplete diagnosis, creating a ticket and escalating bypasses the opportunity for immediate first-level support, and putting the user on hold indefinitely is unprofessional and may violate service level agreements.

  9. Question 9

    A user’s phone contains customer’s PII. The user cannot have the phone automatically wiped because the data is very valuable.
    Which of the following is the BEST method of securing the phone?

    Show answer & explanation

    Correct answer: A

    Fingerprint lock provides the strongest security for a phone containing valuable customer PII when automatic wipe is not an option. Biometric authentication using fingerprints cannot be shared, guessed, or observed like other authentication methods, and provides unique personal identification. Fingerprint locks also typically include backup authentication methods if the sensor fails. Passcode locks can be observed or guessed through various attacks, swipe locks are the weakest form of screen security and easily bypassed, and PIN locks are susceptible to shoulder surfing and brute force attacks, making fingerprint authentication the most secure option for protecting sensitive data.

Ready for the real thing?

The full 220-1002 simulator has every exam-style question, timed mode, and instant scoring.