CompTIA · linux

CompTIA A+ Core 1 & 2

Hardware, networking, mobile devices, OS troubleshooting, and operational procedures. The foundational IT support certification.

14Modules
45 hoursDuration
beginnerLevel

Course Modules

📱
Module 1 — Core 1
Mobile Devices
2 lessons
Laptops and phones are where every IT support shift begins. The exam tests what's field-replaceable inside a laptop (M.2 modules, SO-DIMM, ribbon-cabled keyboards/displays) versus what's soldered, then jumps to connectivity: USB-C for everything modern, Lightning as the Apple legacy, NFC/Bluetooth/IR for short-range pairing and contactless. Know what each connector can actually carry and what the range looks like in centimeters versus meters.
1.1 Laptop Hardware Components

Every laptop ticket collapses into two questions: is this part field-replaceable or soldered, and does the replacement physically key into the slot. A+ almost never asks you to explain how an IPS panel works — it hands you a machine, a symptom, and a parts list, and checks whether you order the right module. Learn the slot-and-key map once and the ordering decisions stop being guesswork.

Key Concepts

  • Laptop displays use LCD (TN, IPS, VA panels) or OLED technology with LED backlighting. Resolution ranges from 1366x768 (HD) to 3840x2160 (4K UHD). Digitizers enable touchscreen input, and replacements require careful ribbon cable disconnection.
  • Batteries and power in laptops are typically lithium-ion (Li-ion) or lithium-polymer (LiPo). Battery calibration, cycle count monitoring, and proper charging practices extend lifespan. Swollen batteries are a safety hazard and must be replaced immediately.
  • Keyboards and input devices connect via ribbon cables to the motherboard. Laptop keyboards are typically membrane-style and can be replaced individually. Trackpads use capacitive touch and may include gesture support for multi-finger input.
  • Wireless cards and expansion include Wi-Fi and Bluetooth adapters using M.2 (Key A/E) or Mini PCIe form factors. Antenna wires route through the display bezel for optimal signal. Cellular cards (WWAN) enable mobile broadband connectivity via SIM slots.
  • Memory and storage upgrades in laptops use SO-DIMM (DDR4/DDR5) modules and 2.5-inch SATA or M.2 NVMe drives. Access panels on the bottom of the laptop provide upgrade access, though some ultrabooks have soldered components that cannot be replaced.
Exam Tip: Know the difference between M.2 key types — Key B is for SATA SSDs, Key M is for NVMe SSDs, and Key A/E is for wireless cards. The exam frequently tests which components can be field-replaced in laptops versus which are soldered.

💻 Concrete example — a battery swap that turns into a slot audit

Ticket: "My laptop only runs on the charger, and the trackpad clicks weird now." You flip it over: the bottom cover bows outward. That is a swollen Li-ion pack pressing up into the trackpad from below — the "weird click" is the tell, not a separate fault.

Walk: 1) Power off, unplug, and stop using the machine — never puncture, bend, or "test" a swollen cell. Order the exact OEM part number; a generic pack with the right connector is still the wrong chemistry and capacity. 2) The user also asked for an SSD upgrade while it is open, so check the slot before ordering: the service manual lists one M.2 2280 slot. If it is Key M, an NVMe drive works; if the board only wires that slot for SATA, an NVMe stick seats but never enumerates. 3) Same audit for RAM — this model has 8 GB soldered plus one free SO-DIMM slot, so the maximum you can sell the user is 8 GB soldered + one module, not a matched pair.

Verify: After the swap the cover sits flush and the trackpad clicks evenly. In Device Manager the new drive shows under Disk drives, and Task Manager → Performance → Memory reports the combined total. Dispose of the old pack through the e-waste stream, never the general bin.

Key takeaway: M.2 key codes decide what fits — Key B = SATA SSD, Key M = NVMe SSD, Key A/E = Wi-Fi/Bluetooth card. A swollen battery is an immediate, non-negotiable replacement, and before quoting any upgrade, confirm what is soldered versus socketed on that specific model.
1.2 Mobile Device Connectivity & Accessories

Connector and radio questions look like trivia, but the exam always wraps them in a scenario: a user wants one cable, or a device pairs at the desk and dies down the hall. What you actually need is a two-column map — what can this connector carry (data, video, power) and how far does this radio reach. Range in centimetres versus metres is the discriminator the question is really testing.

Key Concepts

  • USB-C and Lightning connectors are the primary wired interfaces for modern mobile devices. USB-C supports USB 3.2/4.0, Thunderbolt 3/4, DisplayPort Alt Mode, and Power Delivery (up to 240W). Lightning is Apple-proprietary and limited to USB 2.0 speeds.
  • Bluetooth technology enables short-range wireless communication for peripherals (headphones, keyboards, speakers). Bluetooth 5.0+ offers improved range (up to 240m), speed (2 Mbps), and low-energy (BLE) operation for IoT devices. Pairing requires discovery mode and PIN verification.
  • NFC (Near Field Communication) operates at 13.56 MHz within a range of about 4 cm. Used for contactless payments (Apple Pay, Google Pay), quick Bluetooth pairing, and access badge systems. NFC is a passive technology that does not require battery power on the tag side.
  • Infrared (IR) blasters provide line-of-sight control of TVs, projectors, and media devices. IR communication is unidirectional and requires direct line of sight with no obstructions between sender and receiver.
  • Mobile accessories include docking stations (USB-C hubs with HDMI, Ethernet, USB-A ports), portable hotspots, styluses with pressure sensitivity, and protective cases with integrated battery packs. Wireless charging uses the Qi standard at 5W–15W.
Exam Tip: Memorize USB-C capabilities — it can carry data, video, and power simultaneously. The exam also tests NFC range (~4 cm) and Bluetooth classes (Class 1 = 100m, Class 2 = 10m). Know that IR requires line of sight while Bluetooth and NFC do not.

💻 Concrete example — one cable for the exec's desk

Request: An executive wants a single cable at the desk: external monitor, wired Ethernet, keyboard/mouse, and charging — and wants the same setup to work with their iPhone.

Walk: 1) The laptop side is easy: a USB-C dock carries all four, because USB-C can move data (USB 3.2 / USB4 / Thunderbolt), video (DisplayPort Alt Mode), and power (PD, up to 240 W) on one connector. Check the laptop's port icons — a plain USB-C port without the DP or Thunderbolt marking will charge and move data but never drive the monitor. 2) The phone side does not follow: if it is a Lightning iPhone, that port is Apple-proprietary and capped at USB 2.0 speeds, so a dock will not give it desktop video — that is a spec ceiling, not a bad cable. 3) The badge reader beside the monitor is NFC at about 4 cm, so the user must tap it, not wave from the chair; the conference-room projector remote is IR and needs unobstructed line of sight, which is why it stops working when someone parks a laptop bag in front of it.

Verify: Monitor lights up on the single cable, the laptop battery icon shows charging, Ethernet shows a wired connection, and the badge tap registers at contact distance. Document that the phone is charge-and-sync only on this dock.

Key takeaway: USB-C is the only connector that carries data, video, and power at once — but only if the port supports DisplayPort Alt Mode. Range is the other half of the exam answer: NFC ≈ 4 cm, Bluetooth Class 2 ≈ 10 m, Class 1 ≈ 100 m, and IR needs line of sight.
Key takeaways
  • M.2 key codes: Key B = SATA SSD, Key M = NVMe SSD, Key A/E = wireless card. The wrong key won't physically seat — exam scenario answer for "won't fit".
  • USB-C carries data (USB 3.2 / USB 4 / Thunderbolt), video (DisplayPort Alt Mode), and power (PD up to 240 W) on one connector. Lightning is Apple-only and capped at USB 2.0 speeds.
  • Range cheat-sheet: NFC ≈ 4 cm (contactless), Bluetooth Class 2 ≈ 10 m, IR needs line-of-sight, Wi-Fi passes through walls. Match the technology to the failure mode.
⚡ Mini-quiz — Drill M.2 key types, USB-C capabilities, and the NFC/IR/Bluetooth range cheat sheet.
Quick quiz →
🌐
Module 2 — Core 1
Networking Fundamentals
3 lessons
TCP/IP is the operating system of every IT job. The exam pins specific ports (HTTP 80, HTTPS 443, SSH 22, RDP 3389, DNS 53, SMB 445…), demands you place each device at the correct OSI layer (hub = L1, switch = L2, router = L3), and tests the private IPv4 ranges plus the IPv6 link-local prefix fe80::. The same questions show up again as troubleshooting scenarios — DHCP failure looks like APIPA, DNS failure looks like "name not resolved".
2.1 TCP/IP, Ports & Protocols

Ports look like pure memorization, and half the exam value is exactly that. The other half is the pairing: for every plaintext protocol there is an encrypted replacement on a port you also have to know, and A+ loves to hand you an audit finding and ask what you swap it for. Hold the plaintext → encrypted pairs and the TCP vs UDP split, and most of these questions answer themselves.

Key Concepts

  • TCP vs UDP are the two primary transport-layer protocols. TCP (Transmission Control Protocol) is connection-oriented with three-way handshake (SYN, SYN-ACK, ACK), guaranteeing reliable, ordered delivery. UDP (User Datagram Protocol) is connectionless with no delivery guarantee, used for speed-sensitive applications like DNS queries, VoIP, and video streaming.
  • Well-known ports must be memorized: HTTP (80), HTTPS (443), SSH (22), Telnet (23), DNS (53), DHCP (67/68), SMTP (25), POP3 (110), IMAP (143), FTP (20/21), SFTP (22), RDP (3389), SMB (445), SNMP (161/162), LDAP (389), LDAPS (636).
  • IPv4 addressing uses 32-bit addresses in dotted-decimal notation (e.g., 192.168.1.1). Private address ranges are 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. Subnet masks define network and host portions. CIDR notation (/24 = 255.255.255.0) simplifies subnet representation.
  • IPv6 addressing uses 128-bit hexadecimal addresses (e.g., 2001:0db8::1). Link-local addresses start with fe80::, and the loopback address is ::1. IPv6 eliminates the need for NAT and uses SLAAC (Stateless Address Autoconfiguration) or DHCPv6 for address assignment.
  • The OSI model has seven layers: Physical (1), Data Link (2), Network (3), Transport (4), Session (5), Presentation (6), Application (7). The TCP/IP model simplifies this into four layers: Network Access, Internet, Transport, and Application. Understanding which protocols and devices operate at each layer is critical.
Exam Tip: Port numbers are heavily tested. Create flashcards for all well-known ports. Remember that HTTPS (443), SSH (22), and SFTP (22) are encrypted, while HTTP (80), Telnet (23), and FTP (21) send data in plaintext. The exam expects you to identify which protocol to use based on the scenario.

💻 Concrete example — an audit finding on a branch switch

Finding: A vulnerability scan on the branch office reports "cleartext management protocols enabled" on a switch and a file server. You run netstat -an on the file server and see listeners on 21 and 23.

Walk: 1) Map each port to what it does and whether it encrypts. 23 is Telnet — remote CLI in the clear, including the password. Its replacement is SSH on 22. 21 is FTP control, also cleartext; the replacement is SFTP, which rides the same port 22 because it is a subsystem of SSH. 2) Enable SSH on the switch, disable the Telnet transport, and move the file transfers to SFTP. 3) Do not touch the DNS listener on 53 just because it appears "unencrypted" — DNS queries are normally UDP 53, chosen for speed with no handshake, and the scanner is flagging protocol design, not a misconfiguration.

Verify: Re-run netstat -an: 21 and 23 are gone, 22 is listening. Connect once with an SSH client to prove management still works before you leave the site — disabling the only working transport is how a hardening change becomes an outage.

Key takeaway: Learn the ports in encrypted/plaintext pairs — 22 SSH/SFTP replaces 23 Telnet and 21 FTP, 443 HTTPS replaces 80 HTTP. TCP does the three-way handshake for reliable delivery; UDP skips it for speed, which is why DNS, DHCP, and VoIP live there.
2.2 Network Hardware

The device questions on A+ are OSI-layer questions in disguise. A switch cannot fix a routing problem and a router cannot fix a duplicate MAC, so once you place the device at the right layer, the scenario narrows to one plausible answer. The second half of the lesson is cabling, where the exam's favourite trap is a distance limit rather than a speed limit.

Key Concepts

  • Routers operate at Layer 3 (Network) and forward packets between different networks using IP addresses and routing tables. They perform NAT (Network Address Translation) to allow private IP addresses to communicate on the internet, and can implement ACLs (Access Control Lists) for basic traffic filtering.
  • Switches operate at Layer 2 (Data Link) and forward frames within a local network using MAC addresses and a CAM (Content Addressable Memory) table. Managed switches support VLANs, port security, spanning tree protocol (STP), and link aggregation. Unmanaged switches are plug-and-play with no configuration options.
  • Wireless access points (APs) extend the wired network to wireless clients using Wi-Fi standards: 802.11a (5 GHz, 54 Mbps), 802.11n/Wi-Fi 4 (2.4/5 GHz, 600 Mbps), 802.11ac/Wi-Fi 5 (5 GHz, 6.9 Gbps), 802.11ax/Wi-Fi 6 (2.4/5/6 GHz, 9.6 Gbps). Antenna types include omnidirectional and directional.
  • Firewalls inspect and filter traffic based on rules. Hardware firewalls sit at the network perimeter, while software firewalls run on individual hosts. Next-generation firewalls (NGFWs) add deep packet inspection, application-layer filtering, and intrusion prevention capabilities.
  • Patch panels and structured cabling organize network connections in a server room or wiring closet. Patch panels terminate horizontal cable runs and connect to switches via short patch cables. Cable types include Cat 5e (1 Gbps, 100m), Cat 6 (10 Gbps at 55m), and Cat 6a (10 Gbps at 100m).
Exam Tip: Know the OSI layer at which each device operates — hubs at Layer 1, switches at Layer 2, routers at Layer 3. The exam will test you on cable categories and their maximum speeds and distances. Remember that Cat 6 supports 10 Gbps only up to 55 meters, while Cat 6a extends this to the full 100 meters.

💻 Concrete example — a 10 Gbps link that negotiates at 1 Gbps

Ticket: A new 10 Gbps NAS in the wiring closet links to the core switch at only 1 Gbps. Both ends are rated 10 Gbps and the cable is Cat 6, freshly terminated.

Walk: 1) Check the physical layer first, because that is where the negotiation happens. The run is measured at roughly 80 m through the ceiling. Cat 6 carries 10 Gbps only to about 55 m; past that it falls back to 1 Gbps. Nothing is broken — the cable spec is doing exactly what it says. 2) Replace the run with Cat 6a, which holds 10 Gbps across the full 100 m, and re-terminate both the patch panel and the keystone with the same T568B pinout used everywhere else in the building. 3) While you are in the closet, the user also reports "the guest Wi-Fi can see the accounting share." That is not a cabling issue at all: the guest AP is plugged into an untagged port in the same Layer 2 broadcast domain. Fixing it means a VLAN on the switch, not a new cable or a router change.

Verify: The switch port now shows a 10 Gbps full-duplex link, and a file copy to the NAS sustains far above the old ceiling. Update the cable map with the new Cat 6a run and its measured length.

Key takeaway: Place the device before you troubleshoot — hub = Layer 1, switch = Layer 2 (MAC, CAM table, VLANs), router = Layer 3 (IP, NAT, routing). On copper, Cat 6 does 10 Gbps only to ~55 m; Cat 6a does it to the full 100 m.
2.3 Network Configurations

DHCP, DNS, VLANs, and VPNs are the four configuration surfaces behind almost every "it worked yesterday" ticket, and each fails with its own fingerprint: DHCP failure shows up as an APIPA address, DNS failure as "works by IP, fails by name", a VLAN mistake as "connected but isolated", and a VPN split-tunnel choice as "some things reach, others do not". Learn the fingerprints and you skip straight to the right subsystem.

Key Concepts

  • DHCP (Dynamic Host Configuration Protocol) automatically assigns IP addresses, subnet masks, default gateways, and DNS servers to clients via the DORA process: Discover, Offer, Request, Acknowledge. DHCP leases have configurable durations, and DHCP reservations bind a specific IP address to a MAC address for devices that need consistent addressing.
  • DNS (Domain Name System) translates domain names to IP addresses using a hierarchical system of root servers, TLD servers, and authoritative name servers. Common record types include A (IPv4), AAAA (IPv6), MX (mail), CNAME (alias), PTR (reverse lookup), TXT (SPF/DKIM), and NS (name server).
  • VLANs (Virtual Local Area Networks) logically segment a physical network into separate broadcast domains at Layer 2. VLAN tagging uses IEEE 802.1Q to identify VLAN membership on trunk ports. VLANs improve security by isolating traffic (e.g., separating guest Wi-Fi from corporate network) and reduce broadcast traffic.
  • VPN (Virtual Private Network) creates an encrypted tunnel over a public network. Site-to-site VPNs connect two networks (using IPSec), while client-to-site VPNs allow remote users to access corporate resources. Split tunneling sends only corporate-bound traffic through the VPN, while full tunneling routes all traffic through it.
Exam Tip: Memorize the DHCP DORA process and common DNS record types. The exam often presents scenarios where you must troubleshoot IP address conflicts (duplicate DHCP assignments) or DNS resolution failures. Know that APIPA addresses (169.254.x.x) indicate DHCP failure.

💻 Concrete example — a new guest VLAN that leaves clients stranded

Change: You add VLAN 30 for guest Wi-Fi so visitors stop landing on the corporate network. After the change, guests associate to the SSID, get a Wi-Fi icon — and every one of them ends up with a 169.254.x.x address.

Walk: 1) That address is APIPA, so the client never completed DORA (Discover, Offer, Request, Acknowledge). The radio works; the Layer 2 path to the DHCP server does not. 2) Check the switch port feeding the AP. It is a trunk carrying VLAN 10 (corporate) but VLAN 30 was never added to the allowed list, so the 802.1Q-tagged guest frames are dropped at the first hop. Add VLAN 30 to the trunk. 3) Guests now get an address but cannot resolve names: the guest scope was handing out the internal DNS server, which does not answer queries from that subnet. Change the scope option to a public resolver for guests only. 4) Leave the corporate VPN alone — remote staff use a client-to-site IPSec tunnel with split tunnelling, so only corporate-bound traffic crosses it. Routing guest traffic through it would be the opposite of the isolation you just built.

Verify: A test phone on the guest SSID gets a 10.30.x.x lease, resolves an external site, reaches the internet, and gets no response when pinging the accounting server. Record the VLAN ID and scope options in the network diagram.

Key takeaway: Match the symptom to the service — APIPA (169.254.x.x) = DHCP never answered, "IP works, name does not" = DNS, "connected but isolated" = VLAN/trunk tagging. VLAN traffic crosses a trunk only if that VLAN is tagged and allowed on the port.

🖥 Field call — APIPA address, no internet

Ticket: "My computer says 'No internet access' since this morning. I haven't changed anything." Your first move is ipconfig /all: the IPv4 address shows 169.254.x.x — APIPA, meaning the DHCP handshake failed.

Walk: 1) ping 192.168.1.1 (the gateway) — times out. The client can't reach the router so routing isn't the only issue. 2) Log into the router admin → Status → DHCP client table — the device isn't listed because the pool is exhausted (50 leases, all taken by stale guest devices). 3) Free two stale leases on the router, then on the client run ipconfig /release followed by ipconfig /renew — the client immediately picks up a valid 192.168.1.x address.

Verify: ipconfig /all now shows a real IP with gateway and DNS. ping 8.8.8.8 succeeds. Document: "DHCP pool exhaustion — reduced guest lease time to 2 hours and set stale-lease threshold."

Key takeaways
  • Memorize the well-known ports cold: 22 SSH, 53 DNS, 80 HTTP, 443 HTTPS, 445 SMB, 3389 RDP. Plaintext vs encrypted drives the "what should we replace" question (Telnet/23 → SSH/22).
  • APIPA 169.254.0.0/16 = DHCP failure. If a client shows that range, the DHCP server or path is broken, not the IP stack on the workstation.
  • Cable spec: Cat 6 hits 10 Gbps only to 55 m; Cat 6a extends 10 Gbps to the full 100 m. The exam loves to pin this to a "long server-room run" scenario.
⚡ Mini-quiz — Drill well-known ports, OSI-layer-to-device mapping, and APIPA-as-DHCP-failure diagnostics.
Quick quiz →
🖥
Module 3 — Core 1
Hardware
3 lessons
Inside the box: motherboard form factors (ATX / mATX / mini-ITX), Intel LGA vs AMD AM4/AM5 sockets, DDR4 vs DDR5 (different notches — not interchangeable), and PCIe lane allocation. RAID levels and the SATA-vs-NVMe split each generate their own exam cluster, and the PSU 80-Plus rating ladder plus connector inventory shows up under power.
3.1 Motherboards, CPUs & RAM

Desktop builds and upgrades are a compatibility matrix, and the exam grades you on whether you check it before the parts arrive. Socket, chipset, memory generation, form factor, and power connector all have to agree; get one wrong and the build does not boot or the part physically will not seat. DDR generations are the classic trap, because they are keyed differently on purpose.

Key Concepts

  • Motherboard form factors determine the physical layout and expansion capabilities. ATX (305x244mm) is the standard full-size board with 7 expansion slots. Micro-ATX (mATX, 244x244mm) is smaller with 4 slots. Mini-ITX (170x170mm) is compact with 1 slot, ideal for small form factor builds. The form factor dictates case compatibility, power connector placement, and I/O panel layout.
  • CPU socket types must match the motherboard. Intel uses LGA (Land Grid Array) sockets such as LGA 1700 (12th–14th Gen) and LGA 1200 (10th–11th Gen). AMD uses PGA (Pin Grid Array) with AM4 and the newer LGA-based AM5 socket. Multi-core processors, hyper-threading (Intel) and SMT (AMD) allow simultaneous processing of multiple threads.
  • RAM specifications include DDR4 (1.2V, speeds 2133–3200+ MHz) and DDR5 (1.1V, speeds 4800–6400+ MHz). DIMMs are used in desktops and SO-DIMMs in laptops. Dual-channel configurations require matching pairs installed in the correct slots (typically alternating colors). ECC (Error-Correcting Code) RAM detects and corrects single-bit errors, used in servers and workstations.
  • PCIe expansion slots come in x1, x4, x8, and x16 sizes. PCIe 4.0 x16 provides approximately 32 GB/s bandwidth, while PCIe 5.0 doubles that. Graphics cards use x16 slots, NVMe SSDs use x4 (via M.2), and network cards typically use x1 or x4. PCIe is backward and forward compatible — a smaller card works in a larger slot.
  • BIOS/UEFI firmware initializes hardware during POST (Power-On Self-Test) and hands off to the operating system boot loader. UEFI replaces legacy BIOS with a graphical interface, support for drives larger than 2.2 TB (GPT), Secure Boot to prevent unauthorized OS loading, and faster boot times. Firmware updates (flashing) should be performed carefully to avoid bricking the board.
Exam Tip: Know that DDR4 and DDR5 are not interchangeable due to different notch positions. The exam tests UEFI features like Secure Boot and TPM integration. Remember that ATX uses a 24-pin main power connector and an 8-pin CPU power connector.

💻 Concrete example — the RAM that will not go in

Ticket: A user bought 32 GB of DDR5 for their two-year-old desktop and says "the slot must be broken — it will not push down."

Walk: 1) Nothing is broken. DDR4 and DDR5 are not interchangeable: the notch sits in a different position specifically so the wrong generation cannot seat, and they run at different voltages (DDR4 at 1.2 V, DDR5 at 1.1 V). Identify what the board takes before ordering — the board is LGA 1700 but a DDR4 variant, so the correct part is DDR4 DIMM, not the DDR5 the user bought. 2) Confirm the rest of the matrix while you are in there: the CPU socket must match physically and the chipset must support that CPU generation, often after a UEFI update. 3) The user also wants a GPU in the top slot — that is PCIe x16; a x4 card will run in it, but a x16 card in a x4 slot is bandwidth-starved. 4) Power: the ATX board needs the 24-pin main plus the 4/8-pin EPS CPU connector. A build that spins fans but never POSTs is very often a forgotten EPS plug.

Verify: Correct DDR4 modules seat with an audible click on both retention clips. POST completes, and UEFI reports the full capacity at the expected speed — enable the memory profile if it defaults to the JEDEC base clock. Confirm Secure Boot and TPM are on if the OS deployment needs them.

Key takeaway: Compatibility is checked in this order — form factor, CPU socket and chipset, memory generation (DDR4 and DDR5 are physically keyed apart), then PSU connectors (24-pin ATX + 4/8-pin EPS). UEFI is what gives you Secure Boot, TPM, and GPT support for drives over 2.2 TB.
3.2 Storage Devices

Storage questions come in two flavours: which interface gives the speed the user is paying for, and which RAID level meets a stated requirement. The RAID half is where marks are won and lost, because the exam gives you a drive count and a fault-tolerance requirement and expects you to compute usable capacity on the spot. It also expects you to know that RAID is availability, not backup.

Key Concepts

  • Hard disk drives (HDDs) use spinning magnetic platters and read/write heads. They come in 3.5-inch (desktop) and 2.5-inch (laptop) form factors, with speeds of 5400 RPM (low power) or 7200 RPM (standard performance). HDDs connect via SATA III (6 Gbps) and remain cost-effective for bulk storage but are vulnerable to mechanical failure from drops or vibration.
  • Solid-state drives (SSDs) use NAND flash memory with no moving parts, offering dramatically faster read/write speeds and greater durability. SATA SSDs connect via the same SATA III interface (limited to ~550 MB/s). NVMe SSDs use the M.2 form factor with PCIe lanes, achieving sequential reads of 3500+ MB/s (PCIe 3.0) or 7000+ MB/s (PCIe 4.0).
  • RAID configurations combine multiple drives for redundancy or performance. RAID 0 (striping) splits data across drives for speed but offers no redundancy. RAID 1 (mirroring) duplicates data on two drives. RAID 5 (striping with parity) requires 3+ drives and can survive one drive failure. RAID 10 (1+0) combines mirroring and striping, requiring 4+ drives, providing both speed and redundancy.
  • Drive interfaces and installation vary by type. SATA uses a 7-pin data cable and 15-pin power connector. M.2 slots accept different key types (B key for SATA, M key for NVMe). Hot-swapping is supported by SATA and SAS in server environments. Drive partitioning uses MBR (up to 4 primary partitions, 2 TB max) or GPT (128+ partitions, 9.4 ZB max, requires UEFI).
Exam Tip: RAID is a top exam topic. Remember: RAID 0 = no redundancy, RAID 1 = mirroring (50% usable capacity), RAID 5 = parity (one drive can fail), RAID 10 = mirror + stripe (minimum 4 drives). Know that NVMe SSDs are significantly faster than SATA SSDs because they bypass the AHCI protocol bottleneck.

💻 Concrete example — choosing a level for four 4 TB drives

Requirement: A small office file server has four 4 TB drives. The owner wants "as much space as possible, but the server must keep running if a drive dies."

Walk: 1) Score each level against the requirement. RAID 0 (striping) gives all 16 TB and the best speed but zero redundancy — one drive lost is everything lost, so it fails the requirement outright. RAID 1 (mirroring) survives a failure but gives 50% usable, and with four drives you are running two mirrors. RAID 5 (striping with distributed parity) survives one drive failure and gives (n−1) × 4 TB = 12 TB usable. RAID 10 (mirror + stripe, minimum four drives) gives 8 TB with faster writes and a much quicker rebuild. 2) "Maximum space with single-drive tolerance" points at RAID 5 → 12 TB. Flag the trade-off honestly: a RAID 5 rebuild reads every remaining drive end to end, which is exactly when a second aging drive tends to die. 3) Then say the part that matters most: RAID is not a backup. It survives hardware failure, not deletion, corruption, or ransomware — the array still needs a separate backup job.

Verify: The array reports Optimal with 12 TB usable. Pull one drive on a test window and confirm the volume stays online in Degraded state, then reinsert and watch the rebuild complete before going live.

Key takeaway: RAID 0 = speed, no redundancy; RAID 1 = mirror, 50% usable; RAID 5 = one drive of parity, (n−1) usable; RAID 10 = mirror + stripe, minimum four drives. None of them is a backup.
3.3 Power Supplies & Peripherals

Power is the subsystem people size by guesswork and then troubleshoot for hours. The exam asks it as arithmetic plus an inventory: add the component draw, add headroom, then confirm the PSU physically has the connectors the parts need. A build that boots on the bench and dies under load is nearly always a wattage or rail problem, not a faulty component.

Key Concepts

  • Power supply unit (PSU) ratings follow the 80 Plus certification system: 80 Plus (80% efficiency), Bronze (82%), Silver (85%), Gold (87%), Platinum (89%), Titanium (92%). Higher efficiency means less wasted energy as heat, lower electricity costs, and quieter operation due to reduced cooling demands.
  • Modular vs non-modular PSUs affect cable management and airflow. Fully modular PSUs allow you to connect only the cables you need, improving airflow and aesthetics. Semi-modular PSUs have fixed essential cables (24-pin, CPU) with optional peripheral cables. Non-modular PSUs have all cables permanently attached.
  • Wattage calculation requires adding the power draw of all components (CPU TDP, GPU TDP, RAM, drives, fans) and adding a 20–30% headroom margin. An online PSU calculator can estimate requirements. A typical gaming PC needs 550–750W, while a high-end workstation may require 850W+. Insufficient wattage causes random shutdowns, instability, or failure to POST.
  • Peripheral connectivity includes USB (Type-A, Type-C, Micro-B), video outputs (HDMI 2.1, DisplayPort 1.4, DVI, VGA), and audio (3.5mm jack, S/PDIF optical). Printers connect via USB, Ethernet, or Wi-Fi and require appropriate drivers. Multi-function devices combine printing, scanning, copying, and faxing in one unit.
Exam Tip: Be prepared for questions about PSU connector types: 24-pin ATX motherboard, 4/8-pin CPU, 6/8-pin PCIe (GPU), SATA power (15-pin), and Molex (4-pin legacy). The exam tests your ability to calculate whether a PSU can handle a given component configuration.

💻 Concrete example — sizing a PSU for a GPU upgrade

Request: A workstation with a 500 W non-modular PSU is getting a new GPU. The user reports the machine already reboots during rendering.

Walk: 1) Add it up: CPU 125 W TDP + new GPU 320 W + 64 GB RAM, two NVMe drives, and fans at roughly 50 W together ≈ 495 W. That is essentially the PSU's entire rated output, which explains the reboots — the rail sags under transient load and the supply protects itself. Add the standard 20–30% headroom and you are shopping for ~650–750 W. 2) Check connectors, not just watts: this GPU needs two 8-pin PCIe leads. Daisy-chaining one cable with a pigtail into both sockets is how you get the same instability on a bigger supply. 3) Pick 80 Plus Gold for the efficiency-versus-price sweet spot, and go fully modular so the unused SATA and Molex runs stay out of the case and airflow improves. 4) Inventory the rest of the plugs before closing: 24-pin board, 4/8-pin EPS for the CPU, 15-pin SATA power for drives.

Verify: Run a sustained load for 30 minutes with no reboot, and confirm the 12 V rail stays in spec in the UEFI hardware monitor or a monitoring utility. The old symptom disappearing under the same workload is the proof.

Key takeaway: Size a PSU as total component draw + 20–30% headroom, then verify the connector inventory separately — 24-pin ATX, 4/8-pin EPS for the CPU, 6/8-pin PCIe per GPU lead, 15-pin SATA for drives. Random reboots under load point at power before they point at parts.

🖥 Field call — POST beep loop after RAM upgrade

Ticket: "Tech just upgraded Bob's RAM from 8 GB to 32 GB. Now the PC won't boot — just continuous beeping." Continuous beeps = RAM failure signal on AMI/Phoenix BIOS.

Walk: 1) Power off and unplug. Put on an anti-static wrist strap. 2) Visually confirm: are the new sticks DDR4? Check the board spec — DDR4 and DDR5 have different notch positions and won't seat in the wrong slot. 3) Remove all sticks. Re-seat one stick in Slot 1 (the first channel slot per the motherboard manual — usually the slot furthest from the CPU). 4) Boot — one short beep, POST completes. 5) Add the second stick in its paired dual-channel slot (Slot 3 per the manual). Boot again — success.

Verify: Task Manager → Performance → Memory shows 32 GB at Dual Channel. Document: "RAM mis-seated after upgrade — re-seated both sticks in correct dual-channel slots per motherboard manual."

Key takeaways
  • RAID cheat-sheet: 0 stripe (no redundancy), 1 mirror (50% usable), 5 stripe + parity (3+ drives, one can fail), 10 mirror + stripe (4+ drives, fast and safe).
  • NVMe via PCIe 4.0 ≈ 7000 MB/s — roughly 10× a SATA SSD because it bypasses the AHCI bottleneck. Use NVMe when boot or asset-load time matters.
  • UEFI gives you Secure Boot, GPT partitioning (drives > 2.2 TB), and faster POST than legacy BIOS — the exam tests these features by name and pairs them with TPM 2.0 for BitLocker.
⚡ Mini-quiz — Drill RAID levels, NVMe vs SATA throughput, and UEFI's Secure Boot + GPT advantages.
Quick quiz →
☁️
Module 4 — Core 1
Virtualization & Cloud
2 lessons
Type 1 hypervisors (ESXi, Hyper-V, KVM) run on bare metal — production. Type 2 (VirtualBox, VMware Workstation) run on top of a host OS — labs and dev. Cloud splits into three letters: IaaS (you manage OS + apps), PaaS (you manage apps only), SaaS (you just use it), each on a public / private / hybrid / community deployment. The exam reads as "responsibility shift" pop quizzes.
4.1 Hypervisors & Virtual Machines

Virtualization on A+ is mostly one distinction and one prerequisite. The distinction is Type 1 versus Type 2 — bare metal for production, hosted for the bench. The prerequisite is CPU virtualization support, which is disabled by default on a surprising number of machines and produces an error message that looks like a software bug. Snapshots are the third piece, and they are what makes a risky change reversible.

Key Concepts

  • Type 1 (bare-metal) hypervisors run directly on hardware without a host OS, providing superior performance and security. Examples include VMware ESXi, Microsoft Hyper-V (as a server role), and Citrix XenServer. Type 1 hypervisors are the standard in enterprise data centers and require hardware virtualization support (Intel VT-x or AMD-V).
  • Type 2 (hosted) hypervisors run as applications on top of a host operating system. Examples include VMware Workstation, Oracle VirtualBox, and Parallels Desktop. Type 2 hypervisors are ideal for development, testing, and training environments but add overhead from the host OS layer, resulting in lower performance compared to Type 1.
  • Virtual machine resource allocation involves assigning vCPUs, RAM, virtual disk space, and virtual network adapters to each VM. Over-provisioning (allocating more total resources than physically available) is possible because not all VMs peak simultaneously, but requires careful monitoring to prevent contention and performance degradation.
  • VM snapshots and clones capture the state of a VM at a specific point in time, enabling quick rollback after failed updates or testing. Snapshots should not be used as long-term backups because they grow over time and degrade performance. Cloning creates an independent copy of a VM for rapid deployment of identical environments.
Exam Tip: The key distinction is that Type 1 runs ON the hardware (better for production) and Type 2 runs ON an OS (better for testing). Know that virtualization requires CPU support (VT-x/AMD-V) enabled in BIOS/UEFI. Expect scenario questions about when to use snapshots vs full backups.

💻 Concrete example — "VT-x is not available" on a fresh VM

Ticket: A developer installs VirtualBox on a Windows workstation, creates a 64-bit Linux VM, and gets "VT-x is not available" on start. Reinstalling VirtualBox changes nothing.

Walk: 1) This is a Type 2 (hosted) hypervisor running on top of Windows, and it needs hardware virtualization — Intel VT-x or AMD-V — exposed by the CPU. Reboot into UEFI and enable it; on many OEM machines it ships off. 2) Still failing? Check whether Windows itself has claimed the virtualization extensions. If Hyper-V, Windows Sandbox, or memory integrity is enabled, Windows is acting as the Type 1 hypervisor and owns VT-x, leaving the Type 2 product locked out. Turn the Windows feature off (or move the workload onto Hyper-V) — you cannot have both owning the extensions. 3) Size the VM honestly: assigning every physical core and nearly all RAM to one guest starves the host and makes both slow. Leave the host its share. 4) Before the developer applies an untested patch inside the guest, take a snapshot — that is the whole reason the work happens in a VM.

Verify: The VM boots to the installer. Task Manager → Performance → CPU shows "Virtualization: Enabled". Roll the snapshot back once, deliberately, so the developer has seen it work before they need it.

Key takeaway: Type 1 runs on the hardware (ESXi, Hyper-V, Proxmox — production); Type 2 runs on a host OS (VirtualBox, VMware Workstation — testing). Both need VT-x/AMD-V enabled in UEFI, and only one hypervisor can own those extensions at a time. Snapshot before any change you might need to undo.
4.2 Cloud Models & Services

The cloud questions on A+ are ownership questions. IaaS, PaaS, and SaaS describe how much of the stack somebody else patches, and the shared responsibility model says which side eats the incident when something goes wrong. The reliable exam heuristic: the provider secures the infrastructure of the cloud, the customer secures their data, identities, and configuration in it — at every service level.

Key Concepts

  • Cloud service models define the level of management responsibility. IaaS (Infrastructure as a Service) provides virtual machines, storage, and networking — you manage the OS and applications (e.g., AWS EC2, Azure VMs). PaaS (Platform as a Service) adds runtime and middleware management (e.g., Heroku, Azure App Service). SaaS (Software as a Service) delivers fully managed applications (e.g., Microsoft 365, Google Workspace).
  • Cloud deployment models determine who can access the infrastructure. Public cloud is shared among multiple tenants and managed by the provider (AWS, Azure, GCP). Private cloud is dedicated to a single organization, on-premises or hosted. Hybrid cloud combines public and private, allowing workloads to move between them. Community cloud is shared among organizations with common requirements (e.g., healthcare, government).
  • Cloud characteristics include on-demand self-service, broad network access, resource pooling, rapid elasticity (auto-scaling), and measured service (pay-per-use). These characteristics, defined by NIST, distinguish true cloud computing from traditional hosting and enable organizations to scale resources up or down in response to demand.
  • Shared responsibility model divides security duties between the cloud provider and customer. The provider is responsible for security OF the cloud (physical data centers, hypervisor, network infrastructure), while the customer handles security IN the cloud (data, access controls, OS patching in IaaS, application configuration in PaaS).
Exam Tip: Be able to classify services into IaaS, PaaS, or SaaS based on descriptions. The exam tests the shared responsibility model — know that in SaaS the provider handles almost everything, while in IaaS the customer handles more. Remember the four deployment models: public, private, hybrid, community.

💻 Concrete example — "the provider must have a backup, right?"

Incident: A departing employee's mailbox and OneDrive files are deleted, and 45 days later Finance needs them. The office manager assumes the SaaS provider "obviously has a backup".

Walk: 1) Classify the service first. Hosted email and file storage is SaaS — the provider runs the hardware, the OS, the application, and its patching. That is the maximum a provider covers. 2) Apply the shared responsibility model: even in SaaS, the data, the identities, and the configuration remain the customer's. The provider guarantees the service is available, not that your deleted content survives your own retention settings. Past the default retention window, it is gone unless the tenant enabled a retention policy or a third-party backup. 3) Fix the process, not just the ticket: enable a retention or litigation-hold policy for departing staff, and add an offboarding step that converts the mailbox to shared and exports the files before the account is removed. 4) Contrast the levels so the manager understands the pattern — on IaaS they would also owe the guest OS patching and firewall rules; on PaaS, the application code and its data; on SaaS, only data, access, and settings, which is exactly what failed here.

Verify: The retention policy shows applied in the admin centre, and a test deletion is recoverable after the old window would have expired. Write the offboarding checklist into the knowledge base.

Key takeaway: IaaS = you patch the OS and up; PaaS = you own the app and data; SaaS = you own data, identity, and configuration only. The provider is responsible for the security of the cloud; the customer is always responsible for security in it.
Key takeaways
  • Type 1 hypervisors are for production (no host-OS overhead, hardware virtualization required); Type 2 are for labs and developer machines.
  • Responsibility ladder: IaaS = you patch the OS; PaaS = the provider patches OS and runtime; SaaS = the provider runs everything. The exam asks "who is responsible for X" — pick by service tier.
  • Snapshots ≠ backups: they live on the same storage as the VM, grow over time, and disappear with the host. Real backups land off-host (3-2-1).
⚡ Mini-quiz — Drill Type 1 vs Type 2 hypervisors, the IaaS/PaaS/SaaS responsibility split, and the snapshot-isn't-a-backup pitfall.
Quick quiz →
🔧
Module 5 — Core 1
Troubleshooting Hardware & Networking
2 lessons
CompTIA bakes its 7-step troubleshooting methodology into 15-20% of the exam: identify → theorize → test → plan → implement → verify → document. Hardware symptoms (POST beep codes, overheat throttling, S.M.A.R.T. warnings) and network symptoms (no link, APIPA, DNS-resolution failure) each have signature patterns the exam pins to a specific next-step answer.
5.1 CompTIA Troubleshooting Methodology

The seven-step method is the single most reliably tested thing on A+, and the exam does not test it as a list — it tests it as an order. Scenario questions describe a technician mid-ticket and ask what happens next, and the wrong answers are almost always real actions performed at the wrong step: fixing before testing a theory, or closing before documenting. Know which step you are standing on and the answer is forced.

Key Concepts

  • Step 1: Identify the problem by gathering information from the user, questioning them about recent changes, reviewing logs, and reproducing the issue if possible. Determine the scope (single user, department, or entire network) and identify any environmental or infrastructure changes that may have occurred.
  • Step 2: Establish a theory of probable cause by starting with the most common or simplest explanation first (Occam’s Razor). Consider multiple possibilities, research symptoms online or in knowledge bases, and question the obvious before jumping to complex theories.
  • Step 3: Test the theory to determine the cause. If the theory is confirmed, determine the next steps to resolve. If the theory is not confirmed, establish a new theory or escalate to a senior technician. Testing may involve substituting components, disabling services, or checking configurations.
  • Steps 4–6: Plan, implement, verify — establish a plan of action to resolve the problem and implement the solution (with a rollback plan). Verify full system functionality and, if applicable, implement preventive measures such as updated drivers, firmware patches, or configuration hardening.
  • Step 7: Document findings including the problem description, steps taken, root cause, resolution, and preventive measures. Documentation builds a knowledge base for future troubleshooting and is essential for change management, compliance auditing, and training new technicians.
Exam Tip: CompTIA loves this methodology and tests it frequently. Memorize all seven steps in order: Identify, Theory, Test, Plan, Implement, Verify, Document. Scenario-based questions will ask what you should do FIRST, NEXT, or LAST in a troubleshooting situation.

💻 Concrete example — a BSOD the morning after patch night

Ticket: "My PC blue-screens a few minutes after login. Started this morning. I did not change anything."

Walk: 1) Identify. Question the user and ignore "nothing changed" as a fact — treat it as a starting point. Ask what happened last, check Event Viewer and the BSOD stop code, and confirm whether it reproduces. Update history shows a graphics driver installed overnight. 2) Establish a theory. Simplest cause first: the new driver. Note the alternates you are holding in reserve — failing RAM, overheating — so you are not anchored. 3) Test the theory. Boot into Safe Mode, which loads a generic display driver. No crash after fifteen minutes → theory supported. Had it still crashed, the theory dies and you go back to step 2, not forward. 4) Plan. Roll back the driver in Device Manager, and write the rollback for the rollback: if that fails, System Restore to yesterday's point. 5) Implement. Roll back, then pause that driver update so Windows does not immediately reinstall it. 6) Verify full functionality. Reboot, leave it running under the user's actual workload, confirm the external monitor still works — a fix that breaks the second display is not a fix. Put the preventive measure in place. 7) Document. Symptom, stop code, root cause, action, and the fact the vendor driver is held back pending a newer release.

Verify: No BSOD across a full working day, and the ticket record lets the next technician recognise the pattern on the other machines that got the same driver.

Key takeaway: Identify → Theory → Test the theory → Plan → Implement → Verify full functionality → Document. If the test disproves your theory you go back to establishing a new one, and no ticket is finished until it is written down.
5.2 Common Hardware & Network Issues

This lesson is a symptom-to-subsystem lookup table. A+ describes a machine misbehaving and expects you to name the layer before you name the part: does it fail at power, at POST, after POST, or only under load? "Only under load" and "only after a while" are thermal fingerprints; "never reaches POST" is power or memory; "clicking" is mechanical. Sort the symptom first and you stop replacing working parts.

Key Concepts

  • POST failures and beep codes indicate hardware problems during startup. Continuous beeps typically signal a RAM issue, one long beep with two or three short beeps indicates a video card problem. No video output can mean a dead GPU, unseated RAM, or a failed power supply. Check the motherboard manual for manufacturer-specific beep code meanings.
  • Overheating symptoms include unexpected shutdowns, blue screens (BSOD), system instability, and throttled performance. Causes include failed fans, dried thermal paste, blocked vents, and dust accumulation. Use temperature monitoring software to verify. Reapplying thermal paste and cleaning heatsinks are common resolutions.
  • Network connectivity issues manifest as no internet, slow speeds, or intermittent drops. Troubleshoot methodically: check physical connections and link lights, verify IP configuration (ipconfig/ifconfig), test local connectivity (ping gateway), test DNS resolution (nslookup), test external connectivity (ping 8.8.8.8). An APIPA address (169.254.x.x) indicates DHCP failure.
  • Storage drive failures present as clicking noises (HDD mechanical failure), boot errors ("No boot device found"), corrupted files, or S.M.A.R.T. warnings. SSDs may fail silently with read-only mode as end-of-life behavior. Regular S.M.A.R.T. monitoring, proper backups, and RAID configurations mitigate data loss risks.
Exam Tip: The exam frequently asks about diagnosing no-boot scenarios. Work through the troubleshooting methodology: check power first (fans spinning, lights on), then POST (beep codes), then boot device (BIOS boot order). For network issues, always start with the physical layer and work up the OSI model.

💻 Concrete example — the PC that only dies during long jobs

Ticket: A three-year-old desktop shuts off hard — no BSOD, no warning — roughly twenty minutes into any long export. It runs all day for email without a problem.

Walk: 1) Classify the symptom. It boots, it POSTs, and it survives idle work: that rules out the POST-time faults (a continuous beep pattern would point at RAM, and no video with fans spinning would point at the GPU or power). Failure correlated with sustained load and elapsed time is the overheating fingerprint. 2) Confirm rather than assume: Event Viewer shows Kernel-Power 41, an unexpected loss of power, and a hardware monitor shows the CPU climbing past its throttle point right before each shutdown. 3) Find the cause of the heat. The intake filter and heatsink fins are packed with dust, and the CPU fan spins slowly and unevenly. Blow the dust out with compressed air (short bursts, hold the fan blades still), replace the failing fan, and reseat the cooler with fresh thermal paste. 4) Only after the thermal path is fixed do you consider power — and if the temperatures had been normal all along, an aging PSU would have been the next theory.

Verify: Re-run the same long export while watching temperatures: the CPU now plateaus well under the throttle point and the job completes. Note the dust load in the ticket and put the machine on a cleaning schedule — that is the preventive measure step, not an optional extra.

Key takeaway: Sort by when it fails — no power at all → PSU/outlet; fans spin but no POST → RAM, GPU, or a forgotten EPS connector (listen to the beep codes); shutdowns under sustained load → thermal; clicking plus "no boot device" → a dying HDD, and back it up before anything else.

🖥 Applying the 7-step method — floor printer suddenly offline

Ticket: "All 12 people on the marketing floor can't print since 9 AM." Scope = entire floor = not a single-user issue.

Walk: 1) Identify — ask what changed: "IT ran DHCP renewals last night." 2) Theorize — printer lost its old lease and picked up a new IP. 3) Testping printer-mktg fails; nslookup printer-mktg returns the old IP; check the DHCP client table on the router — the printer's current address is 10.0.1.52 (was 10.0.1.20). 4) Plan — assign a static IP and update DNS to prevent recurrence; notify marketing of a 2-minute outage window. 5) Implement — log into the printer web UI, assign 10.0.1.20/24 static, set gateway and DNS. 6) Verify — test print from three different workstations. 7) Document — "Printer lost DHCP lease after nightly renewal; converted to static with DHCP reservation."

Key takeaways
  • The methodology IS the answer: identify → theorize → test → plan → implement → verify → document. "Document" is always the last step in scenario questions — never skip it.
  • Network "no internet" tree: link light → IP via ipconfig/ip a → ping the gateway → nslookup a known name. Stop at the first failure — that's where the root cause sits.
  • Hardware POST: one beep ≈ OK on most BIOSes; repeating beeps = RAM or video. Re-seat RAM and try a known-good monitor before blaming the motherboard.
⚡ Mini-quiz — Drill the 7-step troubleshooting flow, the ipconfig → ping → nslookup tree, and POST-beep diagnostics.
Quick quiz →
💻
Module 6 — Core 2
Operating Systems
3 lessons
Windows editions (Home / Pro / Pro for Workstations / Enterprise) split by feature, not version number — BitLocker, Group Policy, RDP host, and domain join all live above Home. The CLI portion is non-negotiable: ipconfig, ping, tracert, sfc /scannow, chkdsk, gpupdate. macOS Time Machine, FileVault, and APFS plus Linux package managers (apt vs dnf) round out cross-platform questions.
6.1 Windows Editions & Features

Windows edition questions are feature-gate questions. A+ hands you a business requirement — encrypt the disk, join the domain, push a policy, host a remote session — and checks whether you know that Home cannot do it. The companion concept is the workgroup-versus-domain split, because "each machine keeps its own accounts" versus "one directory authenticates everyone" drives most of the follow-up answers.

Key Concepts

  • Windows editions differ in feature sets. Home is for consumers and lacks Group Policy, BitLocker, Remote Desktop host, and domain join. Pro adds Group Policy, BitLocker, Remote Desktop, Hyper-V, and domain join. Enterprise adds advanced security (AppLocker, Credential Guard, DirectAccess) and volume licensing features. Education mirrors Enterprise with academic licensing.
  • Workgroups vs domains are two network models. Workgroups are decentralized peer-to-peer networks where each computer maintains its own local user accounts — suitable for small networks (under 10 devices). Domains use Active Directory (AD) with a centralized domain controller for authentication, group policy, and resource management, scaling to thousands of users.
  • Windows installation methods include USB boot media (created with Media Creation Tool), PXE (Preboot Execution Environment) network boot for mass deployment, and Windows Deployment Services (WDS). Unattended installations use answer files (unattend.xml) for automated configuration. In-place upgrades preserve user data and applications, while clean installs provide a fresh start.
  • Windows features and tools include Task Manager (performance monitoring, process management), Device Manager (hardware drivers), Disk Management (partition creation, volume extension), and msconfig (boot configuration, startup services). The Control Panel and Settings app manage system configuration, network settings, user accounts, and Windows Update.
Exam Tip: Know which features are exclusive to Pro/Enterprise: BitLocker, Group Policy (gpedit.msc), Remote Desktop host, domain join, and Hyper-V. The exam often asks which Windows edition supports a specific feature. Home edition is the most limited.

💻 Concrete example — a new hire's laptop that cannot join the domain

Ticket: A new starter's laptop, bought retail, needs to join the company domain, get the standard Group Policy, and have its disk encrypted. Domain join is greyed out.

Walk: 1) Identify the edition first: winver (or systeminfo) reports Windows 11 Home. That single fact explains all three requirements failing at once — domain join, Group Policy (gpedit.msc), BitLocker, Remote Desktop host, and Hyper-V are Pro/Enterprise features. Home can be an RDP client, which is why the user insists "remote desktop works". 2) The fix is an edition upgrade, not a rebuild: enter a Pro key under Settings → System → Activation and Windows performs an in-place upgrade, keeping files and applications. Reimaging from the corporate image is the alternative when you also want a clean, standardised build. 3) Then join the domain and let the machine pull policy — this is the moment the workgroup → domain switch happens: authentication moves from the local SAM database to Active Directory, and central policy applies. 4) Enable BitLocker last, once the machine is a domain member, so the recovery key escrows to the directory instead of living on a sticky note.

Verify: winver shows Pro, System properties show the domain, gpresult /r lists the applied policies, and the BitLocker recovery key is visible in the directory. Only then hand over the laptop.

Key takeaway: If the requirement is BitLocker, Group Policy, domain join, RDP hosting, or Hyper-V, the answer is Pro or Enterprise — never Home. Workgroup = per-machine local accounts in the SAM; domain = central Active Directory authentication and policy.
6.2 Windows Command-Line Tools

Command-line questions are graded on exact syntax, because the wrong-answer options are near-miss switches. The other half of the skill is sequencing: several of these tools only work in a particular order, and running the second one first wastes a maintenance window. Learn each command with the problem it solves and the switch that makes it do the thing you actually want.

Key Concepts

  • Network commands are essential for troubleshooting. ipconfig /all displays full TCP/IP configuration, ipconfig /release and /renew reset DHCP leases, ipconfig /flushdns clears the DNS resolver cache. ping tests connectivity, tracert traces the route packets take, nslookup queries DNS servers, and netstat -an shows all active connections and listening ports.
  • System maintenance commands keep Windows healthy. sfc /scannow scans and repairs protected system files. DISM /Online /Cleanup-Image /RestoreHealth repairs the Windows component store. chkdsk /f fixes file system errors, chkdsk /r locates bad sectors and recovers readable data. These commands often require administrator privileges.
  • Group Policy commands manage domain and local policies. gpupdate /force immediately refreshes all Group Policy settings. gpresult /r displays the Resultant Set of Policy (RSoP) for the current user and computer, showing which GPOs are applied. These are critical for troubleshooting policy deployment issues in domain environments.
  • PowerShell extends command-line capabilities with cmdlets following a Verb-Noun syntax (Get-Process, Set-ExecutionPolicy, New-Item). PowerShell supports piping, scripting, and remote management (Enter-PSSession, Invoke-Command). Key cmdlets include Get-EventLog, Get-Service, Test-NetConnection, and Get-WmiObject for system administration tasks.
Exam Tip: Command-line questions are very common. Know the exact syntax: sfc /scannow (not sfc /scan), ipconfig /flushdns, chkdsk /f /r, gpupdate /force. The exam tests what each command does and when to use it. Remember that DISM must be run before sfc if the component store is corrupted.

💻 Concrete example — a mapped drive policy that never arrives

Ticket: A department gets a new mapped drive via Group Policy. Three users have it; one does not, and rebooting has not helped.

Walk: 1) Force a refresh rather than waiting for the background cycle: gpupdate /force reapplies every policy setting immediately. Note the exact switch — /force, not /refresh. 2) Still missing, so find out what the machine actually received: gpresult /r lists applied GPOs and, crucially, the security groups the user is in. The drive-mapping GPO is security-filtered to a group this user was never added to — the policy is working exactly as configured. 3) Add the user to the group. Group membership is read at logon, so a gpupdate /force alone will not do it: the user must sign out and back in. 4) While the user is logged off, they mention name resolution has been odd since an office move. ipconfig /all shows the right server, so clear the stale cache with ipconfig /flushdns, and if a lease looks wrong, ipconfig /release then ipconfig /renew. 5) Their unrelated complaint about explorer crashes gets the repair chain in its required order: sfc /scannow first, and if it reports it cannot fix files, DISM /Online /Cleanup-Image /RestoreHealth to repair the component store, then sfc /scannow again.

Verify: After sign-in, gpresult /r shows the GPO applied and the drive appears in Explorer. sfc /scannow returns no integrity violations on the second pass.

Key takeaway: Memorise the switches exactly — sfc /scannow, DISM /Online /Cleanup-Image /RestoreHealth, gpupdate /force, gpresult /r, ipconfig /flushdns, chkdsk /f /r. Order matters: DISM repairs the source that SFC restores from, and group membership changes need a fresh logon.
6.3 macOS & Linux Basics

A+ is not a Linux exam, but it does expect a working technician's vocabulary on all three platforms: the default file system, the package manager, the backup tool, and enough shell to read a permission string. The highest-value piece is permissions, because "Permission denied" is the one cross-platform error you will meet constantly and it is solvable from the output of a single command.

Key Concepts

  • macOS fundamentals include Finder (file manager), System Preferences/Settings, Spotlight (search), Time Machine (automated backups), FileVault (full disk encryption), and Keychain Access (password management). macOS uses the APFS (Apple File System) for SSDs, supporting snapshots, encryption, and space sharing across volumes.
  • Linux terminal essentials include navigation commands (ls, cd, pwd, mkdir, rmdir), file operations (cp, mv, rm, cat, nano/vi), and permission management (chmod, chown). The Linux file system hierarchy starts at / (root) with /home (user directories), /etc (configuration), /var (logs), /tmp (temporary), and /bin (essential binaries).
  • Package management varies by distribution. Debian/Ubuntu uses apt (apt update, apt upgrade, apt install package-name) with .deb packages. Red Hat/CentOS/Fedora uses yum or dnf with .rpm packages. Package managers handle dependency resolution, updates, and removal automatically from configured repositories.
  • File systems across platforms differ significantly. Windows uses NTFS (permissions, encryption, compression, journaling) and FAT32 (legacy, 4 GB file size limit). macOS uses APFS (SSD-optimized) and HFS+ (legacy). Linux commonly uses ext4 (journaling, up to 1 EB volume size) and XFS (high-performance, scalable). exFAT is the cross-platform choice for USB drives (no file size limit like FAT32).
Exam Tip: Know the default file systems for each OS: Windows = NTFS, macOS = APFS, Linux = ext4. The exam tests basic Linux commands (ls, cd, chmod, grep, sudo) and the difference between apt and yum. Remember that FAT32 has a 4 GB file size limit, making exFAT better for large files on removable media.

💻 Concrete example — "Permission denied" on a shared script

Ticket: A designer copies a backup script from a colleague onto their Ubuntu workstation. Running ./backup.sh returns Permission denied, even though they can open the file in an editor.

Walk: 1) Read the state before changing it: ls -l backup.sh shows -rw-r--r--. Readable, writable by the owner — and not executable by anyone. The file copied fine; the execute bit did not survive. 2) Fix exactly that: chmod +x backup.sh (or chmod 755 backup.sh for owner rwx, group and other r-x). Resist chmod 777 — it is the reflex answer and it is world-writable, which is a security finding rather than a fix. 3) The script then fails writing to /var/backups, a root-owned path, so it needs sudo — elevate the one command, do not log in as root. 4) It calls a tool that is not installed, so use the platform's package manager: sudo apt install rsync on Debian/Ubuntu, where the equivalents would be dnf install on RHEL family and brew install on macOS. 5) Finally the designer wants the output on a USB stick shared with a Mac and a Windows PC. NTFS is awkward on macOS and APFS is unreadable on Windows — format it exFAT, the cross-platform answer.

Verify: ls -l now shows -rwxr-xr-x, the script runs to completion, and the USB stick mounts read-write on all three machines.

Key takeaway: Default file systems are NTFS (Windows), APFS (macOS), ext4 (Linux) — and exFAT when a volume must be shared across all three. Read ls -l before you chmod, use 755 or +x rather than 777, and elevate single commands with sudo.

🖥 Windows repair chain — SFC fails after a botched update

Ticket: "Windows Update failed at 45% last night. Some apps won't open. I ran SFC but it said it couldn't fix all errors."

Why SFC failed: SFC draws from the Windows Component Store. If the store itself is corrupt (which a failed update can cause), SFC can't self-heal. Fix order is DISM first, then SFC.

Walk: 1) Open an elevated command prompt (right-click → Run as Administrator). 2) DISM /Online /Cleanup-Image /RestoreHealth — downloads a clean copy of the component store from Windows Update (5–15 min). 3) Once DISM finishes at 100.0%, run sfc /scannow — now it can access a valid store and actually repair protected files. 4) Reboot. If drive errors are suspected, schedule chkdsk C: /f /r at the next boot (type Y when prompted). 5) Reboot and verify that the previously broken apps launch.

Verify: Second sfc /scannow run reports no integrity violations. Document: "Component store corrupt after failed update; repaired via DISM → SFC → CHKDSK sequence."

Key takeaways
  • BitLocker + Group Policy + RDP-host = Pro and up. Windows Home can't join a domain or run BitLocker — the exam answer is "upgrade to Pro" for any AD-joined or encrypted-disk scenario.
  • Repair stack order: DISM /Online /Cleanup-Image /RestoreHealthsfc /scannowchkdsk /f /r. DISM repairs the component store that sfc depends on; running them out of order is the trap answer.
  • Default filesystems: Windows = NTFS, macOS = APFS, Linux = ext4. FAT32 caps single files at 4 GB — use exFAT for cross-platform USB drives that need to hold a movie file.
⚡ Mini-quiz — Drill Windows-edition features, the DISM → SFC → CHKDSK repair order, and macOS/Linux filesystem equivalents.
Quick quiz →
🔒
Module 7 — Core 2
Security Concepts
2 lessons
Physical security (bollards, mantraps, badge readers, biometrics, CCTV) gates the building; logical security (firewalls, IDS/IPS, ACLs, MFA, least privilege) gates the data. The exam pairs a threat with the matching control — vehicle ramming → bollards, tailgating → mantrap, lateral movement → segmentation + least privilege.
7.1 Physical Security

Physical security questions are matching questions: here is a threat, name the control that stops it. The exam is strict about the pairing — a camera detects but does not prevent, a bollard stops a vehicle but not a person, and only an access control vestibule actually defeats tailgating. Sort each control into deter, detect, or prevent and the scenarios become mechanical.

Key Concepts

  • Bollards are short, sturdy posts installed around building perimeters to prevent vehicle-borne attacks. They can be fixed (permanent), removable, or retractable (hydraulic). Bollards are the first line of physical defense for high-value facilities, data centers, and government buildings where vehicle ramming is a threat.
  • Badges and access control systems use proximity cards, smart cards, or biometric readers to restrict facility access. Badge readers log entry and exit times, creating an audit trail. Tailgating (following an authorized person through a secured door) is countered by security awareness training, mantrap/airlock systems, and anti-passback features that require both entry and exit badge scans.
  • Mantraps (airlocks) are small rooms with two interlocking doors where the second door does not open until the first is closed and locked. This ensures only one authenticated person enters at a time, effectively preventing tailgating and piggybacking. Modern access vestibules may include weight sensors and camera verification.
  • Video surveillance and locks provide detection and deterrence. CCTV cameras (IP-based or analog) monitor entrances, server rooms, and parking areas with motion detection and night vision capabilities. Locks range from traditional key locks (easily defeated by lock picking) to electronic cipher locks (PIN-based), biometric locks (fingerprint, retinal scan), and cable locks for laptops (Kensington lock slots).
Exam Tip: Physical security questions often involve identifying the correct control for a given scenario. Know that mantraps prevent tailgating, bollards prevent vehicle attacks, and cable locks secure laptops. The exam distinguishes between deterrent controls (cameras, signs) and preventive controls (locks, bollards, mantraps).

💻 Concrete example — closing the gaps after a walkthrough audit

Audit findings: An assessor walks into the building behind a staff member, reaches the server room door, and photographs the rack through its window. Management asks for one control per finding.

Walk: 1) Tailgating at the front door. Badge readers are already installed — and they did not help, because the door stayed open for a second person. The control that actually stops it is an access control vestibule (mantrap): two interlocking doors where the second will not open until the first is closed, admitting one person per authentication. 2) No record of who was in the building. Badge readers log every entry, so enable and retain the logs, and pair them with CCTV covering the entrance and the server room door. Be precise about what this buys: cameras are detective and deterrent — they give you the after-the-fact record, they do not stop the entry. 3) Server room reachable by anyone inside. Add a second authentication factor at that door and a physical lock on the rack itself, so a visitor in the corridor is not one handle away from the hardware. 4) The loading dock. The exposure there is a vehicle, not a person, so the control is bollards; fixed for a permanent barrier, removable where delivery trucks need occasional access.

Verify: Re-run the walkthrough. The vestibule refuses the second person, badge logs show the assessor's single entry, the rack is locked, and camera coverage includes both doors with usable footage retention.

Key takeaway: Match the control to the threat — access control vestibule/mantrap stops tailgating, bollards stop vehicles, badge readers authenticate and log, and cameras detect and deter but never prevent.
7.2 Logical Security

Logical security on A+ turns on two comparisons and one principle. The comparisons are IDS versus IPS (alert versus block) and host-based versus network firewall (protects one machine versus the perimeter). The principle is least privilege, which is the correct answer to a startling proportion of "how should this have been configured" questions — including the ones that look like they are about something else.

Key Concepts

  • Firewalls filter traffic based on source/destination IP, port numbers, and protocols. Host-based firewalls (Windows Defender Firewall, iptables) protect individual machines, while network-based firewalls protect entire network segments. Stateful firewalls track connection states and only allow return traffic for established sessions, providing stronger security than stateless packet filters.
  • IDS/IPS (Intrusion Detection/Prevention Systems) monitor network traffic for malicious patterns. IDS is passive and generates alerts without blocking traffic, while IPS is inline and actively blocks detected threats. Both use signature-based detection (matching known patterns) and anomaly-based detection (flagging deviations from normal baselines). UTM (Unified Threat Management) appliances combine firewall, IDS/IPS, antivirus, and content filtering in one device.
  • Access Control Lists (ACLs) define rules that permit or deny traffic based on criteria like source/destination IP, protocol, and port number. ACLs are applied to router interfaces and firewall rules, processed top-down (first match wins), and should always end with an implicit deny rule to block any traffic not explicitly permitted.
  • Principle of least privilege dictates that users, applications, and services should be granted only the minimum permissions required to perform their functions. This limits the blast radius of compromised accounts, reduces accidental data exposure, and is enforced through proper group membership, file permissions (NTFS ACLs), and application-level role-based access.
Exam Tip: Know the difference between IDS (detects and alerts) and IPS (detects and blocks). The exam tests firewall concepts including stateful vs stateless inspection. Remember that ACLs are processed top-down and that the principle of least privilege should guide all access control decisions.

💻 Concrete example — the contractor who was given Domain Admin

Situation: A contractor needs to install a line-of-business application on eight machines for two weeks. Someone puts their account in Domain Admins "so it just works", and the security review flags it.

Walk: 1) Name the violation: least privilege says an account gets the minimum permission needed for the task, for the time it is needed. Domain Admin grants authority over every machine and every account in the domain, permanently, to solve a two-week install on eight endpoints. 2) Right-size it: put the contractor in a group with local administrator rights on those eight machines only, with an expiry date on the account. The install still works and the blast radius drops from the whole domain to eight endpoints. 3) Constrain the network path with ACLs: permit the contractor's subnet to the application server on the ports the app needs and deny the rest — source, destination, protocol, port, which is exactly what an ACL is built to express. 4) The app also needs an inbound port on each workstation, so add a rule to the host-based firewall (Windows Defender Firewall) rather than opening it at the perimeter for everyone. 5) Security asks whether the appliance watching that segment would have caught the misuse: an IDS would have alerted and let the traffic through, an IPS sits inline and can drop it. That difference decides which one belongs where.

Verify: The contractor can install on the eight machines and cannot touch a ninth. The account expires on schedule, and the temporary firewall and ACL rules are removed as part of the same change ticket.

Key takeaway: IDS detects and alerts (passive); IPS sits inline and blocks. Host-based firewalls protect the single machine, network firewalls protect the perimeter, and least privilege — minimum rights, minimum time — is the default correct answer for any over-permissioned account.
Key takeaways
  • Mantraps stop tailgating (interlocked doors, one person at a time). Bollards stop vehicle ramming. Cable locks (Kensington) tether laptops. Match the control to the threat.
  • IDS = detect + alert (passive); IPS = detect + block (inline). UTM bundles firewall + IDS/IPS + AV + content filter into one appliance.
  • Principle of least privilege: grant exactly the permissions needed, no more. The exam frames over-privileged service accounts as a top-tier vulnerability.
⚡ Mini-quiz — Drill mantrap/bollard/cable-lock mapping, IDS vs IPS, and least-privilege framing.
Quick quiz →
⚠️
Module 8 — Core 2
Malware & Social Engineering
2 lessons
Malware categories each have a tell: viruses need a host file, worms self-spread across networks, trojans hide inside legit software, ransomware encrypts data, rootkits persist in the kernel, cryptominers burn CPU/GPU. Social-engineering attacks target people, not systems — the vector (email / phone / SMS / physical) defines the term.
8.1 Malware Types & Removal

Two things get tested here, and only one of them is definitions. Yes, you must tell a worm from a virus from a trojan — but the marks live in the removal order, because CompTIA has a canonical seven-step sequence and the wrong answers are all real steps performed too early. Quarantine before you scan; disable System Restore before you clean; educate before you close.

Key Concepts

  • Viruses require user action to execute and attach themselves to legitimate files or programs, replicating when the host file is run. Worms are self-replicating and spread across networks without user interaction by exploiting vulnerabilities in services. Trojans disguise themselves as legitimate software but perform malicious actions like creating backdoors once executed.
  • Ransomware encrypts the victim's files and demands payment (typically cryptocurrency) for the decryption key. Modern ransomware uses double extortion — encrypting data AND threatening to publish stolen data. Rootkits hide deep in the OS (kernel-level or firmware-level), making them extremely difficult to detect and requiring specialized removal tools or complete OS reinstallation.
  • Spyware and keyloggers covertly monitor user activity. Spyware tracks browsing habits and collects personal data for advertising or theft. Keyloggers record every keystroke to capture passwords, credit card numbers, and messages. Cryptominers hijack system resources (CPU/GPU) to mine cryptocurrency, causing degraded performance, high CPU usage, and increased electricity consumption.
  • Malware removal process follows a specific order: (1) Identify and research malware symptoms, (2) Quarantine the infected system by disconnecting from the network, (3) Disable System Restore to prevent reinfection from restore points, (4) Remediate using updated anti-malware tools in Safe Mode, (5) Schedule full scans and delete infected files, (6) Re-enable System Restore and create a new restore point, (7) Educate the user on safe practices.
Exam Tip: The malware removal steps are tested in order. Remember to quarantine FIRST (disconnect from network), then remediate in Safe Mode. Know the differences between each malware type — the exam gives symptoms and expects you to identify the malware. Rootkits may require boot-level scanning or OS reinstallation to remove.

💻 Concrete example — a fake antivirus popup that disabled Task Manager

Ticket: A workstation shows a full-screen "Your PC is infected — call this number" warning. Task Manager will not open, and the user admits installing a "PDF converter" yesterday.

Walk: 1) Identify and research the symptoms. A bundled installer that disables management tools and displays scareware is a trojan — it arrived disguised as something useful, which is exactly what distinguishes it from a virus (attaches to a host file, needs user execution) or a worm (self-propagates across the network with no user action). 2) Quarantine the system. Disconnect the network first, before any scanning, so nothing calls home or spreads laterally. 3) Disable System Restore. Restore points can hold a copy of the malware and silently reinfect the machine after cleaning. 4) Remediate. Boot into Safe Mode so the malicious components do not load, update the antimalware definitions offline or from a clean machine, then run a full scan and remove what it finds. 5) Schedule scans and run updates. Patch the OS and browser — the delivery vector is usually a known hole. 6) Re-enable System Restore and create a fresh restore point, this time on a clean system. 7) Educate the end user about vetting downloads — skipping this is how the same machine comes back next month.

Verify: Task Manager opens, the popup is gone, a second full scan comes back clean, and the browser has no unexpected extensions. Reconnect the network only after the scan is clean.

Key takeaway: The removal order is fixed — identify, quarantine (disconnect first), disable System Restore, remediate in Safe Mode with updated definitions, schedule scans and patch, re-enable System Restore, then educate the user. Virus needs a host and a user; worm spreads itself; trojan pretends to be legitimate software.
8.2 Social Engineering Attacks

Social engineering questions are identification questions, and the discriminator is almost always the delivery channel: email is phishing, a phone call is vishing, a text is smishing, following someone through a door is tailgating, reading over a shoulder is shoulder surfing. The exam then wants the countermeasure, and for the credential-theft family the countermeasure is nearly always out-of-band verification — confirm through a channel the attacker does not control.

Key Concepts

  • Phishing uses fraudulent emails that impersonate trusted organizations to trick users into clicking malicious links or providing credentials. Spear phishing targets specific individuals using personal information for credibility. Whaling targets executives and high-value individuals. All phishing attacks exploit urgency, authority, and trust to bypass rational decision-making.
  • Vishing and smishing extend phishing beyond email. Vishing (voice phishing) uses phone calls with spoofed caller IDs, often impersonating banks, tech support, or government agencies. Smishing (SMS phishing) sends text messages with malicious links, often claiming package delivery issues, account suspensions, or prize winnings to trick recipients into responding.
  • Tailgating and shoulder surfing are physical social engineering attacks. Tailgating (piggybacking) means following an authorized person through a secured door without badging in. Shoulder surfing involves observing someone entering passwords, PINs, or sensitive data by looking over their shoulder, using binoculars, or positioning cameras. Privacy screens on monitors and awareness training are key defenses.
  • Dumpster diving involves searching through an organization's trash for sensitive documents, hardware with data, or information useful for social engineering (org charts, phone lists, account numbers). Countermeasures include shredding (cross-cut preferred over strip-cut), secure disposal bins, and clear-desk policies. Proper e-waste disposal includes wiping or physically destroying storage media.
Exam Tip: Be able to identify the type of social engineering based on the scenario description. Key indicators: email = phishing, phone call = vishing, text message = smishing, following someone through a door = tailgating, watching someone type = shoulder surfing, searching trash = dumpster diving.

💻 Concrete example — a coordinated attack on the finance team

Incident: In one morning, an accounts clerk gets three contacts. An email from "the CEO" asking for an urgent supplier payment. A phone call from "IT" with a spoofed internal caller ID, asking for their password to fix a mailbox issue. A text with a link to "re-validate your payroll details".

Walk: 1) Name each vector, because the name determines the response. The targeted email using a known executive's identity is spear phishing (business email compromise); the call is vishing; the text is smishing. The shared pattern is manufactured urgency plus a request that bypasses normal process. 2) Give the clerk one rule that covers all three: verify out of band. Call the CEO on the number in the company directory — never a number supplied in the message. Hang up on IT and call the service desk on the published extension; legitimate IT never asks for your password, because they do not need it. Do not tap the link; open the payroll site from a bookmark. 3) Close the process gap that made the payment plausible: require a second approver for supplier bank-detail changes, so a single compromised inbox cannot move money. 4) Check the physical equivalents while you are with the team — finance faces the corridor, so add a privacy filter against shoulder surfing, and get the shredder used for statements to close dumpster diving.

Verify: The clerk reports all three to security instead of acting on them, the supplier change is rejected under the new dual-approval rule, and the message headers confirm the "CEO" address was an external lookalike domain.

Key takeaway: Identify by channel — email = phishing (targeted = spear phishing), phone = vishing, SMS = smishing, through the door = tailgating, over the shoulder = shoulder surfing. The universal countermeasure is out-of-band verification, and nobody legitimate ever asks for your password.

🖥 Field call — browser hijacker + adware

Ticket: "My search engine changed to 'SearchPulse', new toolbars appeared, and there are pop-ups every few minutes."

Walk: 1) Identify — symptoms match a browser hijacker / adware bundle, likely installed via a freeware "custom install" that was clicked through. 2) Quarantine — disconnect from the network immediately (pull Ethernet cable, disable Wi-Fi) to stop any C2 callbacks or lateral spread. 3) Disable System Restore (Control Panel → System → System Protection) — malware can hide in restore points and reinfect after removal. 4) Remediate in Safe Mode — reboot to Safe Mode with Networking; update Malwarebytes definitions; run a full scan; quarantine and delete all detections. 5) Clean the browser — remove all unfamiliar extensions; reset homepage and default search engine. 6) Re-enable System Restore and create a fresh, clean restore point. 7) Educate — show the user the "custom install" option and where to uncheck bundled extras.

Verify: Browser opens to the correct homepage with no toolbars; CPU usage is normal; no ads. Document malware names found and all steps taken.

Key takeaways
  • Removal order: identify → quarantine (disconnect from the network) → disable System Restore → remediate in Safe Mode → re-enable Restore → educate the user. Skipping "disconnect" is the exam's favorite wrong answer.
  • Phishing taxonomy: phishing = mass email, spear-phishing = targeted, whaling = exec-targeted, vishing = voice/phone, smishing = SMS. The vector names the term.
  • Ransomware is defeated by tested, offline backups; paying the ransom is never the exam-correct answer because it funds the attacker and doesn't guarantee a decryption key.
⚡ Mini-quiz — Drill malware categories, the disconnect-first removal flow, and phishing/vishing/smishing terminology.
Quick quiz →
🛡️
Module 9 — Core 2
Windows Security
2 lessons
Windows accounts split into Administrator / Standard / Guest, with NTFS permission inheritance, UAC for elevation prompts, and Group Policy / Local Security Policy for password complexity and lockout. The built-in defense stack is Defender + Firewall + BitLocker — all free, all on by default, and all tested by name on the exam.
9.1 User Account Management

Account management questions test whether you can meet a user's need without handing out administrator rights — that is the answer the exam is fishing for nearly every time. The supporting detail is UAC behaviour, which differs by account type in a way that is directly examinable: administrators get a consent prompt, standard users get a credential prompt, and that distinction is the whole privilege boundary.

Key Concepts

  • User Account Control (UAC) is a Windows security feature that prevents unauthorized changes to the system by prompting for administrator approval when an action requires elevated privileges. UAC levels range from "Always Notify" (most secure) to "Never Notify" (least secure). UAC protects against malware that attempts to silently install or modify system settings.
  • Local vs domain accounts serve different purposes. Local accounts are stored in the SAM (Security Account Manager) database on the individual machine and provide access only to that computer. Domain accounts are stored in Active Directory, authenticated by the domain controller, and provide single sign-on access to network resources across the entire domain.
  • Password policies enforce security requirements for credentials. Key settings include minimum length (12+ characters recommended), complexity requirements (uppercase, lowercase, numbers, symbols), maximum age (requiring periodic changes), password history (preventing reuse of recent passwords), and account lockout threshold (locking after N failed attempts to prevent brute-force attacks).
  • Account types and groups control privilege levels. The built-in Administrator account has full system access and should be renamed and disabled when not in use. Standard user accounts operate with limited privileges. Groups (Administrators, Users, Power Users, Remote Desktop Users) simplify permission management by assigning rights to groups rather than individual users.
Exam Tip: UAC prompts are different for admin vs standard users — admins see a consent prompt, standard users see a credential prompt. Know that domain accounts use Active Directory (centralized) while local accounts use the SAM database (per machine). The exam tests password policy settings configurable through Group Policy or Local Security Policy (secpol.msc).

💻 Concrete example — "just make me an admin so I can install the printer"

Ticket: A user cannot install a departmental printer driver. Windows asks for a username and password, and they want their account added to the local Administrators group to make the prompt stop.

Walk: 1) Read what the prompt is telling you. They are a standard user, so UAC shows a credential prompt asking for an administrator's username and password. An administrator in the same situation would see a consent prompt — just Yes/No — because they already hold the rights and UAC is only asking them to confirm elevation. 2) Do not grant standing admin rights for a one-off install. Type the administrative credentials into the prompt yourself, or deploy the driver centrally by policy so nobody needs elevation at all. That keeps least privilege intact and prevents this account from installing anything else later. 3) Never disable UAC to end the nagging — that removes the elevation boundary entirely and is the wrong answer in every scenario the exam poses. 4) While you are in the console, check the account hygiene the exam expects: the built-in Administrator account should be renamed and disabled, the Guest account disabled, and rights assigned through groups rather than to individuals. 5) Confirm the password policy is enforced centrally — minimum length of 12 or more, complexity, expiration, history, and lockout after a set number of failed attempts.

Verify: The printer installs, the user's account remains a standard user, and net localgroup administrators shows no new member. The policy settings appear under the resultant set of policy rather than as local overrides.

Key takeaway: Standard users get a UAC credential prompt; administrators get a consent prompt — and the answer is to supply credentials for the single task, never to grant standing admin rights or disable UAC. Local accounts live in the SAM; domain accounts live in Active Directory and carry central policy.
9.2 Windows Security Tools

The encryption pair is the examinable core of this lesson: BitLocker encrypts a whole volume and needs Pro or Enterprise plus a TPM, while EFS encrypts individual files and folders on NTFS. The exam builds scenarios around the edition gate and around key recovery, because the failure mode that ends careers is not a broken cipher — it is an encrypted disk whose recovery key nobody can find.

Key Concepts

  • BitLocker provides full-disk encryption for Windows Pro and Enterprise editions. It uses AES encryption (128-bit or 256-bit) and requires a TPM (Trusted Platform Module) chip to store the encryption key securely, or can use a USB startup key as an alternative. BitLocker To Go encrypts removable USB drives. Recovery keys must be saved to Active Directory, Microsoft Account, or printed for emergency access.
  • EFS (Encrypting File System) provides file-level encryption on NTFS volumes, protecting individual files and folders rather than entire drives. EFS is tied to the user's Windows account — only the user who encrypted the files (and designated recovery agents) can decrypt them. EFS and BitLocker can be used together for layered protection.
  • Windows Defender is the built-in antivirus and antimalware solution that provides real-time protection, cloud-delivered protection, and automatic sample submission. Windows Defender Firewall controls inbound and outbound network traffic with rules configurable per network profile (Domain, Private, Public). Windows Security Center provides a unified dashboard for virus protection, firewall, device security, and family options.
  • Windows Update and security patches are critical for closing vulnerabilities. Windows Update delivers security patches, feature updates, and driver updates. Group Policy controls update behavior in enterprise environments. WSUS (Windows Server Update Services) provides centralized patch management, allowing IT to approve, test, and deploy updates across the organization before rollout.
Exam Tip: BitLocker requires TPM + Windows Pro/Enterprise — it is NOT available on Home edition. Know that EFS is file-level (NTFS only) while BitLocker is volume-level. The exam tests Windows Defender Firewall profiles: Domain (joined to domain), Private (trusted home/work), Public (coffee shop, airport — most restrictive).

💻 Concrete example — a stolen laptop and a missing recovery key

Incident: A sales laptop is stolen from a car. Management asks whether the customer data on it is exposed, and wants every laptop encrypted by Friday.

Walk: 1) Establish what protected the stolen machine. It ran BitLocker with the key sealed in the TPM, so the volume is encrypted at rest with AES and the data is not readable by pulling the drive. Note honestly what BitLocker does not cover: it protects data at rest, not a machine that is powered on and unlocked. Adding a pre-boot PIN to TPM raises that bar. 2) Roll out to the rest of the fleet and hit the edition wall — four laptops run Home, which has no BitLocker. Those need an edition upgrade to Pro; there is no supported way to enable full BitLocker management on Home. 3) Escrow the keys before you encrypt anything, not after: recovery keys must land in Active Directory or Entra ID automatically. A recovery key stored only on the encrypted machine is not a recovery key. 4) A user asks about protecting one folder on a shared workstation — that is EFS, file-level encryption on NTFS, tied to the user's certificate. Back that certificate up or the files are unrecoverable when the profile is rebuilt. 5) Confirm the baseline defences are on: Windows Defender real-time protection enabled, definitions current, and Windows Update delivering security patches on schedule.

Verify: manage-bde -status reports the volume fully encrypted and protection on for each laptop, and each machine's recovery key is visible in the directory before the device leaves the office.

Key takeaway: BitLocker = whole volume, Pro/Enterprise only, TPM-backed; EFS = individual files on NTFS, tied to a user certificate. Escrow recovery keys centrally before encrypting, and remember encryption at rest does nothing for a machine that is already unlocked.
Key takeaways
  • NTFS permissions are cumulative across group memberships, but Deny overrides Allow. A user inheriting "Allow Read" from one group and "Deny Read" from another loses access.
  • UAC isn't optional in production — disabling it kills the privilege boundary every modern Windows defense leans on. The exam answer is "leave UAC on".
  • BitLocker = volume-level (Pro+, TPM-backed); EFS = file-level on NTFS (per-user keys). Defender Firewall profiles: Domain / Private / Public (Public is the most restrictive).
⚡ Mini-quiz — Drill NTFS Allow/Deny precedence, the UAC privilege boundary, and BitLocker vs EFS scope.
Quick quiz →
📡
Module 10 — Core 2
Mobile & Embedded Device Security
2 lessons
Phones and tablets are governed by MDM (whole-device control: passcode, remote wipe, encryption, app allow-list) and MAM (app-level control for BYOD containers). IoT and embedded systems (cameras, thermostats, SCADA controllers) usually can't run modern AV — so the standard control is network segmentation plus default-credential change plus firmware updates.
10.1 Mobile Device Management

Mobile management questions are ownership questions wearing a technical hat. The decisive comparison is MDM versus MAM: MDM manages the whole device, MAM manages only the corporate applications and their data. The moment a scenario says BYOD — the device belongs to the employee — whole-device controls become legally and practically wrong, and the containerised answer becomes right.

Key Concepts

  • MDM (Mobile Device Management) allows organizations to centrally manage, configure, and secure mobile devices. MDM solutions (Microsoft Intune, VMware Workspace ONE, Jamf) enforce security policies including password requirements, encryption, app restrictions, and network configurations. Devices can be enrolled manually or automatically through zero-touch enrollment programs.
  • MAM (Mobile Application Management) focuses on securing and managing specific applications rather than the entire device. MAM is particularly useful for BYOD (Bring Your Own Device) scenarios where the organization needs to protect corporate data within apps without controlling the employee's personal device. App wrapping and containerization isolate corporate data from personal data.
  • BYOD vs COPE deployment models define device ownership. BYOD allows employees to use personal devices for work, reducing hardware costs but increasing security challenges. COPE (Corporate-Owned, Personally Enabled) provides company-owned devices that employees can also use for personal tasks, giving IT more control. CYOD (Choose Your Own Device) lets employees select from approved company-purchased devices.
  • Remote wipe and screen locks are critical security features. Remote wipe erases all data on a lost or stolen device to prevent unauthorized access. Screen lock methods include PIN (4–6 digits), pattern, password, fingerprint, facial recognition, and iris scanning. Failed login attempt policies can trigger device lockout or automatic wipe after a configurable number of failures.
Exam Tip: Know the difference between MDM (manages the whole device) and MAM (manages apps only). BYOD scenarios almost always require MAM or containerization to separate personal and corporate data. The exam tests remote wipe as the appropriate response to a lost/stolen device containing sensitive corporate data.

💻 Concrete example — wiping a leaver's phone without wiping their family photos

Situation: An employee resigns. Their work email is on their personal phone under a BYOD arrangement. HR asks IT to "wipe the phone", and the employee objects — it holds years of family photos.

Walk: 1) Both sides are right, and the resolution is the MDM/MAM split. A full remote wipe is an MDM capability: it factory-resets the entire device. On company-owned (COPE) hardware that is exactly what you want. On a personally owned device it destroys personal property. 2) The correct control here is MAM with app protection policies: corporate mail and files live in a managed container, and a selective wipe removes only that container — the account, cached corporate data, and app-level keys — leaving photos, personal apps, and messages untouched. 3) Check the enrolment before promising it: if this phone was enrolled into full MDM at onboarding, the selective option may not exist, and the policy fix is to move BYOD devices onto app-protection-only enrolment. 4) Confirm the baseline mobile controls either way — enforced screen lock with a passcode and short timeout, device encryption, and the ability to locate a lost device. Those are what make a lost phone an inconvenience rather than a breach. 5) Write the difference into the BYOD policy the employee signs, so the wipe scope is agreed before the day it is needed.

Verify: After the selective wipe, corporate mail and files are gone from the phone and the account no longer authenticates, while the personal profile is intact. The management console shows the device as unenrolled from corporate apps.

Key takeaway: MDM manages the whole device (full wipe, passcode policy, encryption) — right for COPE; MAM manages only corporate apps and supports a selective wipe — right for BYOD. Screen lock plus encryption is what turns a lost device into a non-incident.
10.2 IoT & Embedded Systems

IoT and embedded devices are treated on A+ as a network security problem, not a gadget problem. The tested reflex is a two-step: change the default credentials, then segment the device away from everything that matters. These devices ship with published passwords, rarely get patched, and cannot run an endpoint agent — which is precisely why isolation does the heavy lifting.

Key Concepts

  • IoT (Internet of Things) devices include smart home devices (thermostats, cameras, doorbells, speakers), wearable technology (smartwatches, fitness trackers), and industrial sensors. IoT devices often have limited computing resources, making traditional security software impractical. They frequently use default credentials, lack update mechanisms, and communicate over insecure protocols, making them attractive targets.
  • SCADA (Supervisory Control and Data Acquisition) systems monitor and control industrial processes in power plants, water treatment facilities, manufacturing, and oil/gas pipelines. SCADA systems were originally designed for isolated networks (air-gapped) but increasing connectivity exposes them to cyber threats. Securing SCADA requires network segmentation, strict access controls, and specialized industrial firewalls.
  • SoC (System on a Chip) integrates CPU, GPU, memory controller, and I/O interfaces on a single chip, used in smartphones, tablets, and embedded systems (Qualcomm Snapdragon, Apple M-series, Raspberry Pi). RTOS (Real-Time Operating System) provides deterministic response times for time-critical applications like automotive systems, medical devices, and industrial controllers.
  • Smart device security best practices include changing default usernames and passwords immediately, segmenting IoT devices on a separate VLAN or network, regularly updating firmware, disabling unnecessary services and ports, and monitoring network traffic for anomalous behavior from IoT devices. Network-level controls compensate for the limited built-in security of most IoT devices.
Exam Tip: IoT security is increasingly tested. The first step to securing any IoT device is changing default credentials. Network segmentation (placing IoT on a separate VLAN) is the most commonly recommended mitigation. Know that SCADA systems control critical infrastructure and that RTOS is used where precise timing is essential.

💻 Concrete example — smart cameras on the corporate VLAN

Finding: A scan turns up twelve smart cameras and two smart thermostats on the main corporate network. Every camera answers on its web interface with the vendor's documented default credentials.

Walk: 1) Fix the credentials first — it is the highest-value minute of work available. Default usernames and passwords for consumer IoT hardware are published in the manuals and collected in public lists, so anyone who reaches the device already has the password. Set unique, strong credentials on each unit. 2) Then segment. Move the cameras and thermostats onto a dedicated IoT VLAN with firewall rules that permit only what they genuinely need — outbound to the vendor's cloud and inbound from the recording server — and deny lateral traffic to the corporate subnets entirely. This is the control that limits the damage when one of them is inevitably compromised. 3) Update firmware on all fourteen and check whether the vendor still ships updates at all; an end-of-support camera is a permanent liability and the honest recommendation is replacement. 4) Disable the features nobody uses, especially UPnP and remote administration from the internet. 5) Flag the adjacent risk while you are documenting: the building's HVAC controller is a SCADA-class industrial system. It follows the same rules with less tolerance — isolated network segment, tightly controlled access, and vendor-coordinated patching rather than ad-hoc updates.

Verify: From a corporate workstation, the camera web interfaces are unreachable; from the recording server they work. Default credentials no longer authenticate on any unit, and firmware versions are current in the inventory.

Key takeaway: Securing any IoT or embedded device starts with changing default credentials, then putting it on a separate VLAN with no lateral access to production. Keep firmware current, disable unused remote management, and treat SCADA systems as isolated by default.
Key takeaways
  • MDM = whole device (passcode policy, remote wipe, encryption-at-rest, Wi-Fi/VPN profiles). MAM = just the corporate apps (used in BYOD to contain work data without touching personal data).
  • BYOD adds containerization (personal + work side-by-side); COPE keeps the device fully under MDM; CYOD lets the user pick from an approved company catalog.
  • IoT defense = change default credentials + segment to a separate VLAN + update firmware. The exam's "what did the admin do wrong" trope is "put the cameras on the production VLAN".
⚡ Mini-quiz — Drill MDM vs MAM scope, BYOD/COPE/CYOD differences, and the IoT segmentation playbook.
Quick quiz →
📐
Module 11 — Core 2
Networking Security & Troubleshooting
2 lessons
Wi-Fi security has one right answer in 2026: WPA3-Personal (SAE handshake, forward secrecy) or WPA2/WPA3-Enterprise with 802.1X + RADIUS. WEP and WPS are exam-trap "wrong" answers. On the troubleshooting side, the CLI quartet (ping, tracert/traceroute, nslookup, netstat) is what the exam expects you to reach for first.
11.1 Wireless Security

Wireless security is a hierarchy question plus a mode question. The hierarchy is WEP (broken) < WPA/TKIP (legacy) < WPA2/AES-CCMP (baseline) < WPA3/SAE (current). The mode is Personal versus Enterprise: a shared PSK that everybody knows, or per-user credentials validated by a RADIUS server. Scenarios about staff turnover and revoking access are always steering you toward Enterprise.

Key Concepts

  • WPA2 (Wi-Fi Protected Access 2) is the current minimum standard for wireless security. WPA2-Personal uses a pre-shared key (PSK) for authentication, suitable for home and small office networks. WPA2-Enterprise uses 802.1X authentication with a RADIUS server, providing individual user credentials and certificate-based authentication for stronger security in corporate environments.
  • WPA3 improves on WPA2 with Simultaneous Authentication of Equals (SAE), replacing the PSK four-way handshake to protect against offline dictionary attacks. WPA3-Personal provides stronger protection even with simple passwords, while WPA3-Enterprise offers 192-bit cryptographic strength. WPA3 also introduces Enhanced Open (OWE) for encrypted public Wi-Fi without passwords.
  • Encryption protocols have evolved from WEP (broken, never use) to TKIP (WPA, legacy) to AES-CCMP (WPA2, current standard) to AES-GCMP (WPA3). AES (Advanced Encryption Standard) provides strong 128-bit or 256-bit encryption. TKIP was a temporary fix for WEP's weaknesses but is now deprecated. All modern deployments should use AES encryption exclusively.
  • RADIUS (Remote Authentication Dial-In User Service) is the authentication server used in WPA2/WPA3 Enterprise deployments. RADIUS centralizes authentication, authorization, and accounting (AAA) for wireless and wired network access. Users authenticate with individual credentials (username/password, certificates) rather than a shared key, enabling per-user access policies, logging, and revocation.
Exam Tip: Know the wireless security hierarchy: WEP (broken) < WPA/TKIP (legacy) < WPA2/AES (current standard) < WPA3/SAE (latest). Personal mode uses a PSK (pre-shared key), Enterprise mode uses RADIUS. The exam expects you to recommend WPA2-Enterprise with AES minimum for corporate networks.

💻 Concrete example — a departing employee who knows the Wi-Fi password

Situation: An employee leaves on bad terms. Their accounts are disabled the same afternoon — but the office Wi-Fi runs WPA2-Personal, and they know the passphrase, as does every other employee, contractor, and visitor who has ever been given it.

Walk: 1) Understand why disabling the account did not close the gap. With a PSK, the network authenticates the passphrase, not the person. There is no per-user identity to revoke, so the only immediate remedy is rotating the key on the AP and re-entering it on every laptop, phone, printer, and label scanner in the building — which is why nobody ever does it. 2) Rotate it now as containment, then remove the root cause: move the corporate SSID to WPA2/WPA3-Enterprise with a RADIUS server authenticating each user against the directory. From then on, disabling the account also removes network access, with no re-keying. 3) Pick the encryption while you are reconfiguring: WPA3 where the client mix supports it — SAE replaces the WPA2 four-way handshake and blocks the offline dictionary attack against captured handshakes. Where legacy clients force it, run WPA2 with AES-CCMP and never fall back to TKIP or WEP. 4) Leave the guest SSID as a separate WPA2/WPA3-Personal network with client isolation on its own VLAN — a rotating passphrase is acceptable for guests precisely because it grants nothing.

Verify: The leaver's credentials are rejected at the RADIUS server, an active test account loses connectivity within seconds of being disabled, and the AP reports the corporate SSID on WPA3-Enterprise (or WPA2-Enterprise with AES) and the guest SSID isolated.

Key takeaway: WEP < WPA/TKIP < WPA2/AES < WPA3/SAE, and never fall back below AES. Personal uses a shared PSK that cannot be revoked per user; Enterprise uses RADIUS and per-user credentials — the answer whenever the scenario involves turnover or individual accountability.
11.2 Network Troubleshooting Tools

Tool-selection questions give you a symptom and four commands, and the correct one is decided by where you suspect the break. The most valuable diagnostic you own is the split between ping by IP and ping by name: it separates a name-resolution failure from a connectivity failure in one step, and almost every network ticket starts by landing on one side of that line.

Key Concepts

  • ping sends ICMP echo request packets to test basic connectivity between two hosts. A successful ping confirms that the network path is functional, DNS resolution works (if using a hostname), and the target host is reachable. Common results include "Request timed out" (host unreachable or firewall blocking), "Destination host unreachable" (routing issue), and TTL expired (too many hops).
  • tracert (Windows) / traceroute (Linux/macOS) displays the path packets take to reach a destination, showing each router hop along the way with round-trip times. This identifies where packets are being delayed or dropped. High latency at a specific hop indicates congestion at that router. Asterisks (*) indicate a hop that did not respond, often due to ICMP being blocked by a firewall.
  • nslookup queries DNS servers to resolve domain names to IP addresses and vice versa. It can specify a particular DNS server to query (nslookup domain.com 8.8.8.8), check different record types (set type=MX), and identify DNS configuration problems. If nslookup fails but ping to an IP works, the issue is DNS resolution rather than network connectivity.
  • netstat and pathping provide detailed network analysis. netstat -an shows all active connections and listening ports with numeric addresses (useful for identifying rogue connections or verifying services are running). pathping combines the functionality of ping and tracert, sending packets to each hop over a period of time and computing statistics on packet loss and latency at each router along the path.
Exam Tip: Troubleshooting tool selection is frequently tested. Use ping for basic connectivity, tracert to find where the path breaks, nslookup to diagnose DNS issues, and netstat to check open ports and connections. If you can ping an IP but not a hostname, the problem is DNS. If you cannot ping anything, check physical connectivity first.

💻 Concrete example — "the intranet is down" (it is not)

Ticket: Several users report the intranet site is unreachable. Others say it is merely slow. The server team insists the server is healthy.

Walk: 1) Split name from path immediately. ping 10.20.5.40 (the server's IP) succeeds with normal round-trip times, while ping intranet.corp.local fails to resolve. Connectivity is fine; this is DNS. That single comparison has already eliminated half the possible causes. 2) Interrogate DNS directly with nslookup intranet.corp.local: the configured resolver returns an old IP from before last week's server migration. Querying the authoritative server explicitly returns the correct address, so the record is right and the cache is stale. 3) Clear it on the client with ipconfig /flushdns, and get the stale entry corrected on the resolver so you are not repeating this for every user. 4) Now handle the "slow" group, which is a different fault with a different tool. tracert shows normal latency to hop 3 and a sharp jump at hop 4, pointing at one WAN link rather than the server. pathping run over a few minutes quantifies packet loss at that same hop — the evidence to hand the network provider. 5) On the server itself, netstat -an confirms it is listening on 443 and shows established sessions, closing off "the service is not running" as a theory.

Verify: After the flush and the resolver fix, the site resolves to the new IP and loads for the affected users; the slow group improves once the carrier addresses the lossy hop.

Key takeaway: Ping by IP works but ping by name fails → DNS. Neither works → link, IP, or gateway. Use tracert to find where the path degrades, pathping to measure loss at that hop, nslookup to interrogate a resolver, and netstat -an to prove what is actually listening.

🖥 Wi-Fi security audit — legacy WEP on branch office AP

Ticket: "Security audit found WEP encryption on the Westfield branch office AP. Fix it before Friday."

Walk: 1) Log into the AP admin web UI (default gateway address, check DHCP table if unknown). 2) Navigate to Wireless → Security — current setting shows WEP. Change to WPA2-Personal, AES encryption (not TKIP — TKIP is also deprecated and should never be selected). Set a passphrase of 16+ mixed characters. 3) Disable WPS (Wi-Fi Protected Setup) — it has a known brute-force vulnerability that can recover the PSK in hours regardless of passphrase strength. 4) Save and apply. 5) Reconnect all branch devices with the new passphrase; verify each connects successfully.

Verify: A wireless scan from a laptop should show the SSID advertising WPA2 security. Document: "Westfield branch AP migrated from WEP → WPA2-AES; WPS disabled per security policy."

Key takeaways
  • Wi-Fi rank: WPA3 > WPA2 > WPA > WEP. WEP and WPS are never the right exam answer — corporate networks should run WPA2/WPA3-Enterprise with RADIUS.
  • Ping IP works but ping name fails = DNS; ping nothing works = link/IP layer. tracert with `*` asterisks usually means ICMP blocked, not a real outage.
  • netstat -ano on Windows shows listening ports + the PID owning them — perfect for finding rogue listeners or stuck services during triage.
⚡ Mini-quiz — Drill WPA3/WPA2-Enterprise vs deprecated options, the "IP works, name doesn't = DNS" rule, and netstat for triage.
Quick quiz →
📋
Module 12 — Core 2
Operational Procedures
2 lessons
Change management gatekeeps every production touch — RFC + risk assessment + rollback plan + CAB approval + documented outcome. Backups follow the 3-2-1 rule (3 copies, 2 media types, 1 off-site). DR distinguishes RTO (how long can we be down?) from RPO (how much data can we lose?), and hot / warm / cold sites trade cost against recovery speed.
12.1 Documentation & Change Management

Change management is examined as a sequence with a gate, and the gate is approval. Nearly every wrong answer in this section is a competent technician doing the right technical work at the wrong moment — implementing before the change is approved, or closing the ticket before the documentation and diagrams are updated. Know what must be true before you touch the system.

Key Concepts

  • Network diagrams and documentation provide visual representations of the network topology, including physical layouts (cable runs, rack locations, device placement) and logical layouts (IP addressing schemes, VLANs, subnets). Accurate, up-to-date documentation is essential for troubleshooting, onboarding new staff, disaster recovery, and compliance audits. Tools like Visio, Lucidchart, and draw.io are commonly used.
  • Baselines establish normal operating parameters for systems, networks, and applications (CPU usage, memory consumption, network throughput, response times). Comparing current performance against documented baselines helps identify anomalies that may indicate problems or security incidents. Baselines should be updated periodically as infrastructure changes.
  • Knowledge bases are centralized repositories of technical solutions, troubleshooting guides, and documented procedures. They reduce resolution times by allowing technicians to reference solutions to previously encountered problems. Effective knowledge bases include searchable articles with problem descriptions, root causes, resolution steps, and related resources.
  • Change management process ensures that modifications to IT systems are planned, approved, tested, and documented to minimize disruption. The process includes: (1) submit a change request, (2) assess risk and impact, (3) obtain approval from the Change Advisory Board (CAB), (4) plan the implementation with a rollback plan, (5) implement during a maintenance window, (6) verify and document results. Emergency changes follow an expedited process.
Exam Tip: Change management is heavily tested. Know the complete process from request through documentation. The exam will ask what should happen BEFORE making a change (get approval, create a rollback plan) and AFTER (verify functionality, document). A maintenance window minimizes impact on users.

💻 Concrete example — a "quick" firewall rule for the new payment app

Request: Finance needs an inbound rule at the perimeter for a new payment application, live Monday. Your manager asks you to "just add it before you leave".

Walk: 1) Raise a change request rather than editing the rule base. The RFC states the purpose, the exact rule (source, destination, port, protocol), and the requester. Anything touching the perimeter is not a standard pre-approved change. 2) Write the scope and risk analysis: which systems are affected, what the blast radius is if the rule is wider than intended, and the risk level. Note the alternative you rejected — a VPN-only path — and why. 3) Write the rollback plan before implementation, because "remove the rule and restore the saved configuration" only works if you exported that configuration first. Export it now. 4) Get approval from the change board and schedule a maintenance window outside business hours. This is the step the scenario is testing: approval precedes implementation, always. 5) Implement in the window, test the application path end to end, and confirm nothing else broke. 6) Update the artefacts: the network diagram gains the new flow, the rule base gains a comment with the change number, and the knowledge base gains an article so the next technician knows why the rule exists. 7) Compare against the baseline afterwards — if firewall CPU or throughput has moved materially, you know it was this change.

Verify: The payment app connects, an unrelated service is spot-checked as unaffected, the diagram matches reality, and the change record shows approval timestamped before implementation.

Key takeaway: The order is request → scope and risk → rollback plan → approval → scheduled implementation → verification → documentation. Approval comes before you touch anything, and the ticket is not closed until diagrams, the knowledge base, and the baseline are updated.
12.2 Disaster Recovery & Backup

Backup questions are arithmetic against two numbers. RPO is how much data you can afford to lose, and it sets your backup frequency; RTO is how long you can afford to be down, and it sets your restore method and site strategy. Pick the backup type by which restore chain fits inside the RTO — that is the calculation the exam actually wants, alongside the 3-2-1 rule.

Key Concepts

  • Backup types serve different purposes. A full backup copies all selected data (longest time, easiest restore). An incremental backup copies only data changed since the last backup of any type (fastest backup, slowest restore — requires all incrementals plus the last full). A differential backup copies all data changed since the last full backup (moderate speed, requires only the last full plus the latest differential).
  • The 3-2-1 backup rule is the industry standard: maintain 3 copies of your data, on 2 different types of media (e.g., local disk + cloud, or NAS + tape), with 1 copy stored offsite (cloud storage, remote facility). This strategy protects against hardware failure, ransomware, natural disasters, and theft. Test backup restorations regularly to verify data integrity and recovery procedures.
  • RTO and RPO define recovery objectives. Recovery Time Objective (RTO) is the maximum acceptable time to restore operations after a disaster — a 4-hour RTO means systems must be back online within 4 hours. Recovery Point Objective (RPO) is the maximum acceptable amount of data loss measured in time — a 1-hour RPO means backups must occur at least every hour. Lower RTO/RPO values require more expensive infrastructure.
  • Disaster recovery sites vary in readiness and cost. A hot site is a fully operational duplicate of the production environment, ready to take over immediately (most expensive, lowest RTO). A warm site has hardware and connectivity but requires data restoration and configuration (moderate cost and RTO). A cold site is an empty facility with power and network connections that must be fully built out (cheapest, highest RTO).
Exam Tip: Backup types are always tested. Remember: Full (everything), Incremental (since last any backup), Differential (since last full backup). Restoring from incrementals requires the full backup plus every incremental in sequence. The 3-2-1 rule and the definitions of RTO/RPO are frequently tested concepts.

💻 Concrete example — designing to a 1-hour RPO and a 4-hour RTO

Requirement: A firm's order system may lose at most one hour of data (RPO = 1 hour) and must be back within four hours (RTO = 4 hours). Today it runs one nightly full backup to a local NAS.

Walk: 1) Test the current design against the numbers and it fails immediately: a nightly full means a failure at 16:00 loses the whole working day — roughly eight hours against a one-hour RPO. Frequency must rise to hourly. 2) Choose the type by restore chain. A full every hour is the fastest restore but the heaviest to run. Incrementals back up everything since the last backup of any kind — smallest and quickest to write, but a restore needs the last full plus every incremental since, and eleven of those inside a four-hour RTO is a real risk. Differentials back up everything since the last full: they grow through the day but restore from exactly two pieces, the full plus the latest differential. Weekly full + nightly full + hourly differentials meets both numbers with the shortest chain. 3) Apply 3-2-1: three copies, on two different media types, with one off-site. The current design has one copy on one NAS in the same building — a fire or ransomware event takes production and backup together. Add cloud or rotated offline media, and keep at least one copy immutable or offline so encryption cannot reach it. 4) Match the site to the RTO: a four-hour target rules out a cold site; a warm site fits, and a hot site is the near-zero-downtime option if the budget allows.

Verify: Run a real restore, not a job-status check. Time it end to end, restore to a scratch server, and confirm the application opens the data. A backup that has never been restored is an assumption, not a backup.

Key takeaway: RPO sets frequency, RTO sets the restore method. Incremental = since the last backup (smallest, longest chain); differential = since the last full (larger, restores from two pieces); full = biggest, fastest to restore. Follow 3-2-1 — 3 copies, 2 media types, 1 off-site — and test the restore.

🖥 Disaster recovery — ransomware encryption at 2 AM

Ticket: "File server is showing ransom notes. All shared documents are .locked files. Marketing can't work."

Walk: 1) Do NOT pay — payment funds the attacker and guarantees nothing. 2) Isolate immediately: pull the server's network cable to stop lateral spread to other shares and backup paths. 3) Check the backup log: per the 3-2-1 policy there is a full backup on the NAS from Friday night and an incremental from Sunday night (RPO target = 8 hours). 4) Spin up an alternate file server; restore the Friday full, then apply the Sunday incremental on top — data is back within 4 hours (RTO target). 5) Validate: have three managers spot-check their own folders for integrity. 6) Wipe and rebuild the infected server from a known-good image — do not restore it in-place. 7) Document the full incident timeline, RPO and RTO achieved, attack vector, and preventive measures added (additional email filtering, patch schedule, AP segmentation).

Outcome: RPO (data age at recovery) ≈ 8 hours. RTO (time to restore operations) = 3.5 hours. Both within policy. Submit incident report to CAB post-mortem.

Key takeaways
  • 3-2-1 backup: 3 copies, 2 different media types (disk + tape or disk + cloud), 1 stored off-site. Single-site backups die with the building during a real disaster.
  • RTO = Recovery Time Objective (how fast back up); RPO = Recovery Point Objective (how much data loss is tolerable). Lower numbers = more expensive infrastructure.
  • DR site tier: hot (live mirror, lowest RTO, highest $$) → warm (hardware ready, restore needed) → cold (empty room, cheapest, longest RTO). Pick by what you can afford to lose.
⚡ Mini-quiz — Drill 3-2-1 backups, RTO vs RPO framing, and hot/warm/cold DR site trade-offs.
Quick quiz →
🖨
Module 13 — Core 2
Scripting & Remote Access
2 lessons
Scripting languages cluster by environment: PowerShell + batch on Windows, Bash on Linux/macOS, Python when the script must run anywhere. Remote-access tools split into encrypted (SSH 22, RDP 3389, MSP tools over HTTPS) versus deprecated cleartext (Telnet 23, raw VNC). You won't write code on the exam — but you must identify script extensions and pick the right remote-access port for the OS.
13.1 Basic Scripting

You are not asked to write code on A+. You are asked to recognise a script by its extension, know which platform runs it, and understand the risk of executing one. The extension-to-language map is free marks, and the second half — unintended consequences and execution policy — is where the scenario questions live, because running an unvetted script is how a helpful automation becomes an outage.

Key Concepts

  • PowerShell scripts (.ps1) are the primary automation tool for Windows administration. PowerShell uses Verb-Noun cmdlets and supports variables, loops, conditionals, functions, and piping. Execution policies (Restricted, AllSigned, RemoteSigned, Unrestricted) control which scripts can run. Common automation tasks include user account creation, system inventory collection, log analysis, and configuration management.
  • Bash shell scripts (.sh) automate tasks on Linux and macOS. Scripts begin with a shebang line (#!/bin/bash), use chmod +x to make them executable, and support variables, loops (for, while), conditionals (if/then/else), and functions. Common uses include automated backups, log rotation, system monitoring, and batch file processing. Bash is the default shell on most Linux distributions.
  • Python scripts (.py) are cross-platform and widely used for IT automation, network management, and data processing. Python's readable syntax and extensive standard library make it ideal for tasks like API interactions, file manipulation, web scraping, and system administration. Batch files (.bat) are legacy Windows scripts using cmd.exe commands for simple task automation.
  • JavaScript (.js) and VBScript (.vbs) serve different scripting needs. JavaScript runs in web browsers and Node.js for server-side automation. VBScript is a legacy Windows scripting language that runs via Windows Script Host (wscript/cscript), used in older login scripts and administrative tasks. Understanding script file extensions helps identify potential malicious scripts — unexpected .ps1, .vbs, .bat, or .js files may indicate an attack.
Exam Tip: You do not need to write scripts for the exam, but you must identify script types by their file extensions: .ps1 (PowerShell), .sh (Bash), .py (Python), .bat (Batch), .js (JavaScript), .vbs (VBScript). Know that PowerShell execution policies control script execution and that malicious scripts are a common attack vector.

💻 Concrete example — a logon script blocked by execution policy

Ticket: A colleague sends a .ps1 file that maps departmental drives at logon. On the test machine it fails: "running scripts is disabled on this system".

Walk: 1) Identify the file type before anything else. .ps1 is PowerShell, the Windows automation language built on Verb-Noun cmdlets. The error is not a bug — it is the default execution policy refusing to run unsigned scripts, a safety feature doing its job. 2) Read the script before you loosen anything. It maps drives, and it also contains a line that deletes a temporary folder — on a path that resolves to the user's Documents folder on machines with a different profile layout. That is the unintended consequence the exam warns about, and it is why "just run it" is the wrong answer. Fix the path first. 3) Set the policy at the appropriate scope: Set-ExecutionPolicy RemoteSigned allows local scripts and requires a signature on downloaded ones — a proportionate setting. Do not use Unrestricted to make an error go away. 4) Test on one machine before deploying to the department, and roll it out through Group Policy rather than emailing the file around. 5) Recognise the neighbours while you are here: .sh is Bash for Linux/macOS (needs a #!/bin/bash shebang and chmod +x), .py is Python and cross-platform, .bat is legacy Windows Batch, .vbs is VBScript, and .js is JavaScript.

Verify: The corrected script maps the drives on the test machine, the temporary-folder line targets the intended path, and nothing in the user's Documents folder is touched. Only then does it go into the logon policy.

Key takeaway: Know the extensions cold — .ps1 PowerShell, .sh Bash, .py Python, .bat Batch, .vbs VBScript, .js JavaScript. Always read a script before running it, and set execution policy to the least permissive setting that works, never Unrestricted.
13.2 Remote Access Technologies

Remote access is tested on ports and on session semantics. The ports are pure recall. The semantics are the part that decides real tickets: RDP creates a new, separate session and disconnects the console user, while VNC and screen-sharing tools attach to the session already on screen. Choose wrongly and you log the user out of the very thing you were asked to look at.

Key Concepts

  • RDP (Remote Desktop Protocol) uses port 3389 and provides full graphical remote access to Windows systems. RDP supports encryption, Network Level Authentication (NLA), and multi-monitor configurations. It should be protected with strong passwords, MFA, and VPN tunneling — exposing RDP directly to the internet is a major security risk due to brute-force and exploit attacks.
  • VNC (Virtual Network Computing) uses port 5900 and provides platform-independent remote desktop access. Unlike RDP, VNC shares the existing desktop session (not a separate session), so both local and remote users see the same screen. VNC is useful for cross-platform support but typically lacks the encryption and performance optimization of RDP, requiring SSH tunneling for secure access.
  • SSH (Secure Shell) uses port 22 and provides encrypted command-line remote access to Linux, macOS, and network devices. SSH replaces the insecure Telnet protocol (port 23, unencrypted). SSH supports key-based authentication (more secure than passwords), port forwarding/tunneling (encrypting other protocols through SSH), and secure file transfer via SCP and SFTP.
  • VPN and screen-sharing solutions provide additional remote access methods. VPNs create encrypted tunnels to access entire networks remotely (IPSec for site-to-site, SSL/TLS for client-to-site). MSRA (Microsoft Remote Assistance) allows a technician to view or control a user's screen with the user's permission. Third-party tools like TeamViewer, AnyDesk, and Zoom screen sharing enable ad-hoc remote support sessions.
Exam Tip: Memorize the port numbers: RDP = 3389, VNC = 5900, SSH = 22, Telnet = 23. Know that SSH is encrypted while Telnet is not. RDP creates a new session while VNC shares the existing session. The exam tests when to use each remote access method based on the scenario (OS, security needs, user involvement).

💻 Concrete example — helping a user without kicking them off

Ticket: A user cannot get a spreadsheet macro to run and asks you to "look at my screen". They are mid-document with unsaved changes.

Walk: 1) Do not reach for RDP. On a Windows workstation it opens a new session on port 3389 and disconnects the console user — you would see a clean desktop, they would lose their screen, and the error you were called about would not be in front of you. 2) Use a screen-sharing or remote-assistance tool that attaches to the existing sessionVNC on port 5900 behaves this way by design, and so do the built-in quick-assist style tools. Both of you see the same desktop, and the user can watch what you change, which is also better support. 3) The user then asks you to fix "the same problem" on the Linux build server. That is a command-line job: SSH on port 22, encrypted, with key-based authentication preferred over passwords. Its unencrypted ancestor Telnet on port 23 is never the answer. 4) Their final request — "can I RDP in from home?" — gets a firm no in that form. Never expose 3389 directly to the internet; it is scanned constantly and brute-forced. Put it behind a VPN so the tunnel authenticates first, and require multi-factor authentication on the VPN.

Verify: The user keeps their session and their unsaved work while you watch the macro fail, the SSH session authenticates by key, and an external port scan shows 3389 closed from the internet.

Key takeaway: RDP 3389 (new session — disconnects the console user), VNC 5900 (shares the existing session), SSH 22 (encrypted CLI), Telnet 23 (plaintext, never). Remote access from outside goes through a VPN — never expose RDP straight to the internet.
Key takeaways
  • Script-extension cheat sheet: .ps1 PowerShell, .sh Bash, .py Python, .bat Batch, .vbs VBScript, .js JavaScript. Unexpected files with these extensions in email attachments are the malware-attachment scenario.
  • Remote-access ports: SSH 22 (encrypted, Linux/network gear), RDP 3389 (encrypted, Windows graphical), VNC 5900 (cross-platform but needs SSH tunneling), Telnet 23 = exam trap.
  • RDP creates a new session; VNC shares the existing session (both users see the same screen — useful for assist-style support but bad for privacy).
⚡ Mini-quiz — Drill script-extension recognition, SSH vs RDP vs VNC ports, and the new-session vs shared-session distinction.
Quick quiz →
🌱
Module 14 — Core 2
Environmental & Professionalism
2 lessons
ESD (electrostatic discharge) damages components silently — anti-static wrist straps and mats are non-optional bench gear. Fire-suppression class matters (Class C for electrical fires). MSDS / SDS sheets cover chemical handling; e-waste goes to certified recyclers. Professional conduct (active listening, expectation-setting, confidentiality) is its own exam domain — the polite answer almost always wins.
14.1 Safety Procedures

Safety appears on every A+ exam and the answers are non-negotiable rather than situational. Two families matter: protecting the hardware from you (ESD, which damages components at voltages you cannot feel) and protecting you from the hardware (stored charge in power supplies and CRTs, which is lethal after unplugging). Disposal is the third piece, and the document you are expected to name is the SDS.

Key Concepts

  • ESD (Electrostatic Discharge) prevention is critical when handling computer components. ESD can damage sensitive electronics (RAM, CPUs, motherboards) with as little as 30 volts, well below the human perception threshold of ~3,000 volts. Prevention methods include wearing an anti-static wrist strap connected to a grounded surface, using anti-static mats, touching the metal chassis before handling components, and storing parts in anti-static bags.
  • Proper component handling requires holding circuit boards by the edges to avoid touching connectors or traces. CPUs must be aligned with the socket indicator (arrow or notch) and never forced. RAM modules click into place when properly seated. Hard drives should be handled gently to avoid shock damage to platters. Always power off and unplug equipment before servicing internal components.
  • Electrical safety involves understanding the dangers of high-voltage components. CRT monitors and power supplies contain capacitors that retain dangerous charges even when unplugged — never open a power supply. Use surge protectors and UPS (Uninterruptible Power Supply) units to protect equipment. Follow proper grounding practices and never bypass the ground prong on a power cord.
  • MSDS/SDS and proper disposal documents (Material Safety Data Sheets / Safety Data Sheets) contain information about chemical hazards, handling procedures, and emergency response for materials like printer toner, cleaning solvents, and battery electrolytes. E-waste disposal must follow local regulations — batteries, CRT monitors, toner cartridges, and circuit boards contain hazardous materials and should be recycled through certified e-waste facilities, never placed in regular trash.
Exam Tip: ESD prevention appears on every A+ exam. Always use an anti-static wrist strap when handling components. Know that power supplies and CRT monitors are dangerous even when unplugged due to stored charge. MSDS/SDS sheets tell you how to handle hazardous materials safely. Batteries must be recycled, not thrown in the trash.

💻 Concrete example — a RAM upgrade on a carpeted office in January

Job: Add memory to six desktops in a carpeted office in winter, and remove two dead machines — one with a failed PSU, one an old CRT-based till.

Walk: 1) Set up against ESD before opening anything. Dry winter air plus carpet is the worst case; a static discharge you cannot feel is thousands of volts and will damage RAM, a CPU, or a motherboard — sometimes as a latent fault that fails weeks later, which is the expensive kind. Use an anti-static wrist strap clipped to unpainted chassis metal, work on an ESD mat, and keep each module in its anti-static bag until it goes in. 2) Handle correctly: hold boards and modules by the edges, never touching gold contacts or traces, and align RAM by its notch rather than forcing it. 3) The dead PSU is not a repair job. Power supplies hold a lethal charge after being unplugged — never open one. The same rule, more strongly, applies to the CRT: it stores extremely high voltage even when disconnected, so it is never opened and goes out through certified e-waste. 4) Unplug from mains before any internal work — a modern board is still energised at standby with the PSU switch on. 5) For disposal, consult the SDS (Safety Data Sheet) for the battery and toner you are also clearing out: it states the handling, storage, and disposal requirements, and the answer is always the certified recycling stream rather than the general waste bin.

Verify: All six machines POST with the full memory and no intermittent faults over the following week. The PSU and CRT leave on the e-waste manifest, signed and filed.

Key takeaway: Wrist strap to unpainted metal, ESD mat, anti-static bags, hold boards by the edges — ESD kills components at voltages you cannot feel. Never open a PSU or a CRT; they hold lethal charge when unplugged. Check the SDS and use certified disposal for batteries, toner, and displays.
14.2 Communication & Professionalism

The professionalism questions are not filler, and they are not subjective — the expected answer follows a fixed pattern every time: listen fully, do not argue or judge, set a realistic expectation, and respect confidentiality. When a scenario offers a technically clever option and a respectful one, the respectful one is correct. The most-missed detail is privacy: what you see on a user's machine stays there.

Key Concepts

  • Professional appearance and behavior set the tone for customer interactions. IT technicians should maintain a neat, appropriate appearance, arrive on time, and be prepared with the necessary tools and documentation. Avoid using personal devices during service calls, refrain from eating or drinking near customer equipment, and always treat the customer's workspace and data with respect.
  • Active listening is the foundation of effective technical support. Let the user fully describe the problem without interrupting, ask clarifying questions, and repeat back the issue in your own words to confirm understanding. Avoid using jargon — explain technical concepts in plain language that the end user can understand. Never dismiss the user's concerns or make them feel unintelligent.
  • Setting and managing expectations builds trust with users and management. Provide realistic timelines for repairs and communicate proactively if delays occur. If you need to escalate an issue, explain why and provide an estimated timeline for resolution. Document all actions taken, keep the customer informed of progress, and follow up after resolution to confirm the issue is fully resolved.
  • Cultural sensitivity and confidentiality are essential in diverse workplaces. Be respectful of different communication styles, personal space preferences, and cultural norms. Maintain strict confidentiality — never access, read, or share a user's personal files, emails, or browsing history beyond what is necessary to resolve the reported issue. Handle sensitive data according to organizational privacy policies and applicable regulations.
Exam Tip: Professionalism questions test soft skills. The correct answer almost always involves active listening, clear communication, setting expectations, and respecting confidentiality. Never argue with users, never access data beyond what is needed, and always document your work. These questions are straightforward — choose the most professional, respectful option.

💻 Concrete example — an angry user and a laptop full of personal files

Ticket: A user arrives visibly angry: their laptop has been "broken for three days", nobody has updated them, and they have a client deadline tonight.

Walk: 1) Let them finish. Active listening means no interrupting, no defending the service desk, and no jumping to a diagnosis while they are still talking. Take notes, then restate the problem back in your own words so they can hear that you have it right — that alone resolves most of the anger. 2) Do not argue, dismiss the complaint, or blame another team; the three-day gap is a real service failure and acknowledging it costs nothing. Avoid jargon — "the storage device is failing" lands, "the SMART attributes show reallocated sectors" does not. 3) Set a realistic expectation and beat it rather than promising what you cannot deliver: a loaner machine within the hour with their files restored from backup, the failing drive replaced by tomorrow. Then proactively update at the time you said you would, even if the news is "still on track". 4) While recovering data you see personal files, medical documents, and private photos. You do not open them, you do not mention them, you do not comment on them to colleagues — confidentiality is absolute, and a technician who gossips about a user's files is finished. If something appears to breach policy or law, it goes through the defined escalation path, not into a conversation. 5) Take the personal call the user gets mid-handover as your cue to step back and give them privacy rather than hovering.

Verify: The user leaves with a working loaner and their files, and gets the promised update on time. The ticket records the fault and the actions — and nothing about the contents of their documents.

Key takeaway: The scripted correct answer is listen actively, restate the problem, avoid jargon and arguments, set and meet realistic expectations, and keep everything you see confidential. When one option is technically clever and another is respectful of the user, the exam wants the respectful one.
Key takeaways
  • Anti-static wrist strap + ESD mat before opening any device. Discharge can kill RAM, CPU, or a motherboard at voltages humans can't even feel.
  • Power supplies and CRTs hold dangerous charges even when unplugged — never open them. Surge protector + UPS protects the gear that's running.
  • Customer-facing soft skills: listen actively, set expectations, avoid jargon, document everything, and respect confidentiality. The polite-and-thorough option is always the exam-correct answer.
⚡ Mini-quiz — Drill ESD prevention, residual-charge hazards (PSU/CRT), and the polite-and-thorough soft-skill answer pattern.
Quick quiz →
Start practicing →