Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
A help desk team was alerted that a company-owned cell phone has an unrecognized password-cracking application. Which of the following should the help desk team do to prevent further unauthorized installations from occurring?
Mobile Device Management (MDM) is used to control, monitor, and enforce policies on mobile devices. It allows IT teams to restrict app installations, push approved apps, and monitor device compliance. Deploying MDM would prevent unauthorized applications, such as password crackers, from being installed on company-managed devices.
A . Group Policy is for managing Windows environments and not applicable to smartphones.
B . PAM (Privileged Access Management) controls administrative access, not app installation.
C . Anti-malware can help detect malicious apps but doesn't prevent their installation proactively.
CompTIA A+ 220-1102 Objective 2.2: Compare and contrast common security measures and tools.
Study Guide Section: Mobile Device Management (MDM) capabilities --- app control, security enforcement
A company's IT department discovers that unauthorized software has been installed on several workstations. The IT manager requests a review and an update of the workstation security posture, focusing on preventing future unauthorized software installations. Which of the following should the company do?
The correct answer is A. Remove account administrative rights, because unauthorized software installation is most commonly possible when users have local administrator privileges. In Windows environments, installing most applications requires elevated permissions. If users are members of the local Administrators group, they can bypass many built-in security controls and install software without IT approval.
According to the Quentin Docter -- CompTIA A+ Complete Study Guide, the principle of least privilege is fundamental to endpoint security. Users should only be granted the minimum permissions necessary to perform their job functions. Removing administrative rights prevents users from installing unapproved applications and significantly reduces malware risk.
The Travis Everett & Andrew Hutz -- All-in-One Exam Guide explains that while technologies like firewalls, SmartScreen, and Endpoint Detection and Response (EDR) provide important layers of protection, they do not directly stop users from installing software if they already have administrative access. EDR detects and responds to threats, but it does not prevent intentional installation by privileged users.
The Mike Meyers / Mark Soper Lab Manual reinforces that controlling user permissions is the most effective preventive control against unauthorized changes to a system. Removing admin rights stops the root cause rather than reacting after installation occurs.
Therefore, to prevent future unauthorized software installations, removing account administrative rights is the most direct and effective solution, making A the correct answer.
A customer asks a help desk technician for help in selecting new computers. The customer would like to avoid expensive licensing fees but would like all files to be kept locally. Which of the following operating systems should the technician recommend?
The key requirements are (1) avoid expensive licensing fees and (2) keep files locally. Linux best matches both. Quentin Docter explains that open source software is ''freer than free,'' meaning the application is free and the source code is shared, and he explicitly lists ''OSs such as Linux'' as open source examples. That directly supports the licensing-cost goal. By contrast, Windows and macOS are commercial, licensed operating systems.
Chrome OS often works best when users rely heavily on cloud-based services and synchronization, which conflicts with the customer's preference that ''all files be kept locally'' (even though local storage exists, Chrome OS is commonly positioned around cloud workflows). Linux supports fully local file storage and gives the organization control over storage location, backup choices, and offline access.
The All-in-One guide reinforces the idea that some developers (including Linus Torvalds for Linux) made software ''freely available for everyone,'' highlighting Linux as a no-licensing-fee option compared with commercial licensing models. Therefore, the best recommendation is Linux (A).
A technician is creating an MDM policy using hardening techniques that are unique to each user. Which of the following techniques is the technician using?
MDM hardening often includes enforcing stronger authentication on mobile devices. The phrase ''unique to each user'' points to something inherent to the individual---biometrics---rather than something the user knows (password/pattern) or something they have (PIV/smart card). Quentin Docter explains: ''Biometric devices use physical characteristics to identify the user. This type of authentication is considered something that you are,'' and lists common implementations including ''fingerprint... scanners.'' This exactly matches a fingerprint, which is unique per person and commonly enforced via device policies in MDM environments.
Docter also notes mobile devices increasingly implement biometrics for access control, specifically citing ''fingerprint access control'' adopted by manufacturers. A drawn pattern and a password are knowledge factors and can be shared/observed, while a PIV card is a possession factor (something you have) and can be lost or loaned. Because the question specifies a hardening technique ''unique to each user,'' the best match is the biometric factor: fingerprint (B).
Performance on a user's smartphone is degrading. Applications take a long time to start, and switching between apps is slow. Which of the following diagnostic steps should a mobile technician take first?
One of the most common causes for performance degradation on smartphones isstorage or memory overloaddue to excessive apps.Uninstalling unused appsis a basic but effective first diagnostic step.
FromTravis Everett -- All-in-One Exam Guide:
''Start troubleshooting sluggish smartphones by clearing unused apps and files before performing advanced diagnostics or resets.''
312 questions covering all exam domains, starting from $20
4 domains from the CompTIA 220-1202 exam outline, with approximate weightings. Every sample question above is tagged with the domain it comes from
Install and configure Windows, macOS, Linux, and mobile operating systems for end-user environments. Use Task Manager, Command Prompt, Disk Management, and other system tools to manage device performance, troubleshoot issues, and handle file system operations.
Implement encryption, access controls, and wireless security protocols to protect systems and data. Detect, remove, and prevent malware threats using appropriate tools and best practices.
Diagnose and resolve operating system and application issues, including connectivity and performance problems on mobile devices. Address unauthorized access and malware-related security concerns affecting software operation.
Document system changes and follow best practices for configuration management. Establish backup and recovery processes for workstations while adhering to safety protocols and maintaining clear communication with users.
Common questions about the exam itself