CompTIA 220-1202 Practice Exam Questions & Answers

5 Free Questions · Last reviewed: August 30, 2026 · Prepared & Reviewed by the ValidExamDumps Editorial Team

Exam Facts

CompTIA 220-1202 Exam Details

Key details for this exam, checked against the published exam outline

312 Practice Questions (Our Bank)
90 minutes Exam Duration
700 out of 900 Passing Score
USD 165 Exam Fee (United States)
Exam Code
220-1202
Full Name
CompTIA A+ Certification Exam: Core 2
Issuing Body
CompTIA
Question Format (Our Bank)
Multiple Choice, Hotspot
Delivery
Online proctored or at a Pearson VUE test centre
Eligibility
Recommended: 12 months of hands-on experience in an IT support specialist job role
Validity
3 years
Practice Questions

Free 220-1202 Practice Questions

Each question shows the correct answer and an explanation of why it is right

VA
ValidExamDumps Editorial Team Every question and its answer is checked by our 220-1202 exam preparation team, who also write the explanation shown with each one. How we research and review these pages
Question 1

A help desk team was alerted that a company-owned cell phone has an unrecognized password-cracking application. Which of the following should the help desk team do to prevent further unauthorized installations from occurring?

Correct Answer: D
Explanation

Mobile Device Management (MDM) is used to control, monitor, and enforce policies on mobile devices. It allows IT teams to restrict app installations, push approved apps, and monitor device compliance. Deploying MDM would prevent unauthorized applications, such as password crackers, from being installed on company-managed devices.

A . Group Policy is for managing Windows environments and not applicable to smartphones.

B . PAM (Privileged Access Management) controls administrative access, not app installation.

C . Anti-malware can help detect malicious apps but doesn't prevent their installation proactively.


CompTIA A+ 220-1102 Objective 2.2: Compare and contrast common security measures and tools.

Study Guide Section: Mobile Device Management (MDM) capabilities --- app control, security enforcement

Question 2

A company's IT department discovers that unauthorized software has been installed on several workstations. The IT manager requests a review and an update of the workstation security posture, focusing on preventing future unauthorized software installations. Which of the following should the company do?

Correct Answer: A
Explanation

The correct answer is A. Remove account administrative rights, because unauthorized software installation is most commonly possible when users have local administrator privileges. In Windows environments, installing most applications requires elevated permissions. If users are members of the local Administrators group, they can bypass many built-in security controls and install software without IT approval.

According to the Quentin Docter -- CompTIA A+ Complete Study Guide, the principle of least privilege is fundamental to endpoint security. Users should only be granted the minimum permissions necessary to perform their job functions. Removing administrative rights prevents users from installing unapproved applications and significantly reduces malware risk.

The Travis Everett & Andrew Hutz -- All-in-One Exam Guide explains that while technologies like firewalls, SmartScreen, and Endpoint Detection and Response (EDR) provide important layers of protection, they do not directly stop users from installing software if they already have administrative access. EDR detects and responds to threats, but it does not prevent intentional installation by privileged users.

The Mike Meyers / Mark Soper Lab Manual reinforces that controlling user permissions is the most effective preventive control against unauthorized changes to a system. Removing admin rights stops the root cause rather than reacting after installation occurs.

Therefore, to prevent future unauthorized software installations, removing account administrative rights is the most direct and effective solution, making A the correct answer.

Question 3

A customer asks a help desk technician for help in selecting new computers. The customer would like to avoid expensive licensing fees but would like all files to be kept locally. Which of the following operating systems should the technician recommend?

Correct Answer: A
Explanation

The key requirements are (1) avoid expensive licensing fees and (2) keep files locally. Linux best matches both. Quentin Docter explains that open source software is ''freer than free,'' meaning the application is free and the source code is shared, and he explicitly lists ''OSs such as Linux'' as open source examples. That directly supports the licensing-cost goal. By contrast, Windows and macOS are commercial, licensed operating systems.

Chrome OS often works best when users rely heavily on cloud-based services and synchronization, which conflicts with the customer's preference that ''all files be kept locally'' (even though local storage exists, Chrome OS is commonly positioned around cloud workflows). Linux supports fully local file storage and gives the organization control over storage location, backup choices, and offline access.

The All-in-One guide reinforces the idea that some developers (including Linus Torvalds for Linux) made software ''freely available for everyone,'' highlighting Linux as a no-licensing-fee option compared with commercial licensing models. Therefore, the best recommendation is Linux (A).

Question 4

A technician is creating an MDM policy using hardening techniques that are unique to each user. Which of the following techniques is the technician using?

Correct Answer: B
Explanation

MDM hardening often includes enforcing stronger authentication on mobile devices. The phrase ''unique to each user'' points to something inherent to the individual---biometrics---rather than something the user knows (password/pattern) or something they have (PIV/smart card). Quentin Docter explains: ''Biometric devices use physical characteristics to identify the user. This type of authentication is considered something that you are,'' and lists common implementations including ''fingerprint... scanners.'' This exactly matches a fingerprint, which is unique per person and commonly enforced via device policies in MDM environments.

Docter also notes mobile devices increasingly implement biometrics for access control, specifically citing ''fingerprint access control'' adopted by manufacturers. A drawn pattern and a password are knowledge factors and can be shared/observed, while a PIV card is a possession factor (something you have) and can be lost or loaned. Because the question specifies a hardening technique ''unique to each user,'' the best match is the biometric factor: fingerprint (B).

Question 5

Performance on a user's smartphone is degrading. Applications take a long time to start, and switching between apps is slow. Which of the following diagnostic steps should a mobile technician take first?

Correct Answer: D
Explanation

One of the most common causes for performance degradation on smartphones isstorage or memory overloaddue to excessive apps.Uninstalling unused appsis a basic but effective first diagnostic step.

FromTravis Everett -- All-in-One Exam Guide:

''Start troubleshooting sluggish smartphones by clearing unused apps and files before performing advanced diagnostics or resets.''

Get Full Access

312 questions covering all exam domains, starting from $20

Study Guide

What the CompTIA 220-1202 Exam Covers

4 domains from the CompTIA 220-1202 exam outline, with approximate weightings. Every sample question above is tagged with the domain it comes from

Domain 1: Operating Systems 28%

Install and configure Windows, macOS, Linux, and mobile operating systems for end-user environments. Use Task Manager, Command Prompt, Disk Management, and other system tools to manage device performance, troubleshoot issues, and handle file system operations.

Domain 2: Security 28%

Implement encryption, access controls, and wireless security protocols to protect systems and data. Detect, remove, and prevent malware threats using appropriate tools and best practices.

Domain 3: Software Troubleshooting 23%

Diagnose and resolve operating system and application issues, including connectivity and performance problems on mobile devices. Address unauthorized access and malware-related security concerns affecting software operation.

Domain 4: Operational Procedures 21%

Document system changes and follow best practices for configuration management. Establish backup and recovery processes for workstations while adhering to safety protocols and maintaining clear communication with users.

FAQ

220-1202 Exam FAQ

Common questions about the exam itself

What background do I need before taking the 220-1202 exam?
CompTIA recommends 12 months of hands-on experience in an IT support specialist role. You should have practical knowledge of troubleshooting hardware, software, and connectivity issues on Windows, macOS, and mobile devices.
Is the 220-1202 harder than Core 1?
Core 2 focuses more on troubleshooting, security, and operational procedures than Core 1 does. Candidates often find the software troubleshooting and security domains challenging because they require both conceptual understanding and practical decision-making skills.
How long should I study for the 220-1202 exam?
Most candidates spend 4 to 6 weeks preparing, depending on their existing experience. If you have solid hands-on background in IT support, you might prepare in less time. Plan to review all four domains and work through performance-based questions.
What happens on exam day for the 220-1202?
You have 90 minutes to answer a maximum of 90 questions, which include multiple-choice, drag-and-drop, and performance-based questions. Performance-based questions simulate real-world tasks like troubleshooting a system or configuring security settings.
How long is the CompTIA A+ certification valid after I pass 220-1202?
Your CompTIA A+ certification remains valid for 3 years from the date you pass both Core 1 and Core 2. You can renew it by passing the current version of the exams, earning higher CompTIA certifications, or completing approved continuing education.
Can I retake the 220-1202 exam if I fail?
Yes, you can retake the exam, but you must purchase a new voucher each time. CompTIA does not publish a waiting period between retakes, though some testing centers may have their own policies.
What job role does the 220-1202 prepare me for?
The CompTIA A+ certification (both Core 1 and 220-1202) leads to technical support specialist, IT technician, and junior system administrator roles. It demonstrates that you can install, configure, troubleshoot, and secure end-user devices.
Do I need to pass Core 1 before taking 220-1202?
No, you can take the exams in any order. However, you must pass both 220-1201 (Core 1) and 220-1202 (Core 2) to earn the CompTIA A+ certification.
What's the difference between 220-1202 and the older 220-1102 exam?
The 220-1202 (V15) launched March 25, 2025, and replaced the 220-1102 (V14). The new version includes updated content on security, operational procedures, and cloud technologies relevant to modern IT support. CompTIA estimates the 220-1202 will retire around September 2028.