220-1102 Sample Questions & Answers
Windows editions and command-line tooling make up the biggest chunk, alongside wireless-security protocols and authentication methods, malware detection and removal, backup procedures, and troubleshooting common Windows or PC issues.
Launch the full 220-1102 simulator →Showing 5 of 11 free samples.
- Question 1Intermediate
Software Troubleshooting · Mobile OS and application security issues
A user reports that their smartphone is experiencing unusual behavior after downloading a productivity app from the official app store. The device now shows excessive data usage and displays persistent security notifications. Which of the following actions should the technician take FIRST to address this issue?
Show answer & explanation
Correct answer: C
Removing the suspicious application should be the first step when dealing with mobile malware symptoms. Even though the app was downloaded from an official store, malicious applications can still slip through screening processes or become compromised after publication. The symptoms described (high data usage and security warnings) are consistent with malware behavior such as data exfiltration or unauthorized network communications. Uninstalling the app is the least invasive first step that can immediately stop the malicious activity while preserving user data and device configuration. If symptoms persist after removal, additional steps like anti-malware scans or factory reset may be necessary.
- Question 2Beginner
Operational Procedures · Change management best practices
A project steering committee has just approved a software deployment change request. Which of the following represents the MOST appropriate next phase in the change management process?
Show answer & explanation
Correct answer: A
End user acceptance is the logical next step after change approval in the change management process. Once the change advisory board or steering committee approves a change request, the implementation team must validate that affected end users accept the proposed changes and understand the impact on their daily operations. This step ensures stakeholder buy-in before proceeding with implementation and helps identify any overlooked concerns or requirements. End user acceptance also includes confirming that appropriate training and communication plans are in place to support the change rollout.
- Question 3Intermediate
Software Troubleshooting · Malware removal procedures
A user contacts technical support reporting that their workstation files have become inaccessible, and there is a program on the screen demanding cryptocurrency payment to restore access. A technician confirms the system is infected with ransomware. Which of the following should the technician perform FIRST?
Show answer & explanation
Correct answer: A
Isolating the infected system is the first and most critical step in ransomware incident response. This involves immediately disconnecting the affected computer from the network to prevent the ransomware from spreading to other systems, accessing network shares, or communicating with command and control servers. Quarantine can be accomplished by unplugging network cables, disabling wireless adapters, or using network isolation tools. This containment step is essential before any remediation attempts, as it limits the scope of the infection and protects other valuable data and systems on the network. Only after proper isolation should removal and recovery procedures begin.
- Question 4Intermediate
Security · Mobile device security
A corporation is deploying new tablets to sales representatives and needs to ensure corporate data remains protected if devices are lost or stolen. Which of the following security measures provides the BEST protection for this scenario?
Show answer & explanation
Correct answer: D
Remote wipe capability is the most effective security measure for protecting corporate data when mobile devices are lost or stolen. This feature allows IT administrators to remotely erase all data from a device through mobile device management (MDM) solutions, ensuring that sensitive corporate information cannot be accessed by unauthorized individuals. Remote wipe can be triggered immediately upon reporting a lost or stolen device, and it completely removes all data, applications, and settings. This is particularly important for sales representatives who may store customer information, financial data, and proprietary business information on their devices.
- Question 5Beginner
Security · Browser security settings
A user reports that their Windows 11 system is displaying unwanted promotional notifications through the notification center. The notifications appear to originate from a specific website they recently visited. Which of the following is the BEST approach for a technician to resolve this issue?
Show answer & explanation
Correct answer: A
Blocking notifications from the specific website in browser settings is the most targeted and effective solution. Modern web browsers allow websites to request permission to send push notifications, and users can grant or deny these permissions. When unwanted promotional notifications come from a specific website, the best approach is to access the browser's notification settings and move that particular site from the 'Allowed' list to the 'Blocked' list. This resolves the immediate problem without affecting legitimate notifications from other sources or disabling useful browser functionality entirely. This approach maintains system functionality while eliminating the specific nuisance.
Ready for the real thing?
The full 220-1102 simulator has every exam-style question, timed mode, and instant scoring.