220-1201 Cheat Sheet
Mobile Devices
Mobile Device Hardware
Read full chapterCheat sheet
Sharp facts the exam loves — scan these before test day.
- Sort every mobile part into serviceable module or sealed
The first move on any mobile repair is deciding whether a component is a serviceable module or a sealed part. Traditional laptops expose the battery, memory, storage, wireless card, keyboard, and display as replaceable modules, while phones, tablets, and thin ultrabooks increasingly glue or solder those same parts. Whether a part is a module or sealed often decides the job before you open the case.
- Soldered LPDDR memory cannot be upgraded; only SO-DIMMs can
Laptop RAM in a SO-DIMM (small outline dual inline memory module) socket can be swapped or added, but many thin laptops use LPDDR (low-power DDR) chips soldered directly to the board, which are fixed for the life of the device. Before promising a memory upgrade, confirm the machine actually has SO-DIMM slots rather than soldered memory.
Trap Ordering a SO-DIMM upgrade for an ultrabook whose memory is soldered LPDDR; there is no socket to add it to.
- Laptop storage is 2.5-inch SATA, M.2, or soldered eMMC
A serviceable laptop drive is a 2.5-inch SATA disk or an M.2 card, and an M.2 card can run either the SATA or the faster NVMe protocol, so check which the slot supports. Budget and ultrathin devices instead solder eMMC (embedded MultiMediaCard) storage to the board, which cannot be replaced or upgraded.
- The lid is layered: the panel shows the image, the digitizer senses touch
A laptop or tablet lid is a stack of independent layers, so a fault usually lives in one layer, not the whole screen. The panel (LCD or OLED) produces the image, the digitizer senses touch, and the bezel holds the camera, microphone, and Wi-Fi antenna. An image that displays perfectly but ignores touch points squarely at the digitizer, not the panel.
Trap Replacing the whole display panel when only touch has failed; the panel is fine and the digitizer is the faulty layer.
- A laminated screen replaces as one fused assembly
On most phones and many laptops the glass, digitizer, and panel are laminated into a single fused assembly, so you cannot separate cracked glass from a good panel. The repair replaces the whole unit, which is why a glass-only quote is usually wrong on a laminated device.
Trap Quoting a glass-only repair on a laminated screen, where the glass, digitizer, and panel come only as one bonded part.
- LCD needs a backlight; OLED lights each pixel itself
An LCD filters a separate backlight through liquid crystals, so it always leaks some light and cannot reach a true black. An OLED emits light per pixel and switches pixels fully off, giving true blacks and a thinner panel with no backlight layer. This one difference drives most display comparisons.
- TN panels are cheap and fast but shift color off-axis
A TN (twisted nematic) LCD has the fastest response and the lowest cost, but the narrowest viewing angles and weakest color, so brightness and color wash out as you move off-center. It suits budget or high-refresh use where viewing angle does not matter much.
Trap Specifying a TN panel for color-critical or shared-viewing work; its color and viewing angles shift too much for that.
- Choose IPS for wide viewing angles and accurate color
An IPS (in-plane switching) LCD gives the widest viewing angles and the most accurate color of the LCD types, at higher cost and power draw than TN. It is the standard pick for design, photo, and any work where color fidelity or off-angle viewing matters.
- VA panels trade response time for the highest LCD contrast
A VA (vertical alignment) LCD sits between TN and IPS: it offers the highest contrast ratio and deeper blacks than either, but a slower response that can smear fast motion. It fits media viewing where contrast matters more than speed.
- OLED risks burn-in from static on-screen elements
Because each OLED pixel ages with use, a static element held on screen for long stretches, such as a taskbar or a channel logo, can ghost in permanently as burn-in. That makes OLED a poor fit for an always-on display showing fixed content, even though it gives the best blacks and contrast.
Trap Choosing OLED for a 24/7 kiosk or dashboard with a fixed interface; the static elements will burn in over time.
- Only legacy CCFL backlights use an inverter, not LED
A CCFL (cold cathode fluorescent lamp) backlight needs high-voltage AC, so laptops with one carry an inverter that converts the DC supply into that AC. Modern LED backlights run on low-voltage DC and have no inverter, so an inverter is a component only on older CCFL panels.
Trap Trying to replace the inverter on a modern LED-backlit laptop; LED backlights have none, so the dim-display fault is elsewhere.
- Wi-Fi antennas route through the hinge into the lid
Laptop Wi-Fi antenna wires run from the wireless card on the motherboard, up through a hinge, and around the display bezel, because the raised, metal-free lid gives the best reception. Any screen replacement disturbs those leads, so re-seating them is part of the job.
Trap Blaming the wireless card or driver for weak Wi-Fi right after a screen repair, when an unseated antenna lead in the lid is the usual cause.
7 questions test this
- A technician is routing Wi-Fi antenna wires through a laptop chassis after installing a new wireless card. Which of the following practices…
- After replacing a laptop wireless card, a technician confirms the adapter appears in Device Manager with no errors but the laptop cannot…
- A technician has seated a replacement wireless card into a laptop's M.2 slot. Which of the following should the technician perform next to…
- A technician is reassembling a laptop after replacing the display panel. Where should the Wi-Fi antenna wires be positioned for the best…
- When routing Wi-Fi antenna wires through a laptop chassis during reassembly, which of the following practices helps avoid signal…
- When routing replacement Wi-Fi antenna leads through a laptop chassis, which of the following practices should the technician avoid to…
- A technician is installing a Wi-Fi antenna assembly in a laptop. Which of the following locations provides the best wireless signal…
- WLAN cards do Wi-Fi and Bluetooth; WWAN cards do cellular
The internal wireless card is usually an M.2 or Mini-PCIe WLAN (wireless LAN) card that handles Wi-Fi and Bluetooth. Cellular data needs a separate WWAN (wireless WAN) card plus a SIM, which not every laptop includes. Both are field-replaceable modules on many laptops.
- Mobile batteries are lithium-ion or lithium-polymer cells
Mobile devices use lithium-ion (Li-ion) cells, common as rigid rectangular laptop packs, or lithium-polymer (LiPo) cells, whose gel electrolyte can be formed thin and flexible, which is why phones and tablets favor them. Both store high energy in a small space, and both can swell when they fail.
- A swollen battery is a hazard: replace it, never puncture it
A pack that has swelled has failed and is a fire and rupture risk, so take it out of service right away. Never puncture it, force-discharge it, or keep charging it to flatten it, and use a plastic tool rather than a metal pry to remove it. A phone whose screen or back panel is lifting is showing a swollen cell underneath.
Trap Puncturing a swollen pack or continuing to charge it to keep the device running; that risks fire and rupture.
- Disconnect the battery connector before other internal work
After powering down, unplug the battery connector first, before removing or reseating any other internal part, so no rail stays live and a slipped tool cannot short a powered board. This ordering is standard safe practice for laptop, phone, and tablet service.
- Modern batteries are glued in; older packs latch out
Older laptops hold the battery in an external bay that releases with a latch or slide, needing no tools. Most current laptops, and nearly all phones and tablets, bond the cell in with adhesive, so replacement means opening the case and freeing it carefully. Which mounting a device uses sets the whole procedure.
- The built-in webcam and microphone sit in the display bezel
A laptop's built-in webcam and microphone are mounted in the top of the display bezel, alongside the antenna leads. Because they are integrated into the lid, a failed built-in camera often means servicing part of the display assembly rather than swapping a standalone module.
- Camera and ribbon cables use ZIF connectors: lift the tab to release, seat fully, press to secure
Internal ribbon (flat flexible) cables such as a camera module's attach to the logic board through a ZIF (Zero Insertion Force) connector, a socket with a small hinged locking tab. To disconnect, lift the tab first and slide the cable out; to reconnect, lift the tab, slide the aligned cable fully in, and press the tab down to clamp it. A ribbon that is not fully seated, or whose tab is left open, makes no data connection, so a just-replaced camera shows a black screen or streaked images even though the part is good.
Trap Condemning a just-installed camera module as defective when a partially seated ribbon or an unlatched ZIF tab is the real fault.
9 questions test this
- After replacing a front-facing camera module in a tablet, a technician opens the camera application and sees only a black screen. Which of…
- A technician needs to disconnect the camera ribbon cable from a mobile device logic board during a camera module replacement. Which of the…
- A technician needs to reconnect a camera module ribbon cable to a ZIF connector on a smartphone logic board. Which of the following…
- A technician is connecting a replacement camera module ribbon cable to the logic board connector on a smartphone. Which of the following…
- A technician has replaced the rear-facing camera module in a tablet. The device powers on successfully, but the camera application displays…
- A technician is replacing a rear-facing camera in a smartphone and needs to disconnect the camera's flat flexible cable from the logic…
- A technician is replacing the rear camera module on a smartphone. The camera connects to the logic board through a thin flat ribbon cable.…
- A technician is replacing the rear-facing camera module in a smartphone. The camera connects to the logic board using a thin flat ribbon…
- After replacing the rear-facing camera module in a smartphone, a technician notices that captured photos show lines and discoloration…
Mobile Accessories
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Mobile Connectivity
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Mobile Troubleshooting
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Networking
Protocols and Ports
Read full chapterCheat sheet
Sharp facts the exam loves — scan these before test day.
- Use connection-oriented TCP when every byte must arrive in order
TCP is connection-oriented: it opens a session, numbers every byte, acknowledges what arrives, and retransmits anything lost, so data lands complete and in order. That reliability costs setup round trips and header overhead, which is why it carries web, email, and file transfer where a corrupted result is unacceptable.
Trap Choosing UDP for a file transfer that must arrive intact; UDP never retransmits a lost datagram.
8 questions test this
- A technician is configuring a server to host large file downloads for remote users. Which of the following best explains why TCP is…
- A technician needs to transfer a large file to a remote server and must ensure every byte arrives correctly at the destination. Which of…
- Which of the following characteristics of TCP makes it the appropriate transport protocol for file transfers?
- A technician needs to transfer a critical database backup to an offsite server and must ensure the file arrives completely and in order.…
- Which of the following characteristics differentiates TCP from UDP at the transport layer?
- A technician is setting up a system to transfer critical financial reports between branch offices. The data must arrive complete and in the…
- Which of the following TCP features ensures that data segments arrive at the destination in the correct order?
- A technician is comparing TCP and UDP. Which of the following is a feature that TCP provides but UDP does not?
- UDP is connectionless: no handshake, no acknowledgment, no reordering
UDP sends each datagram on its own with almost no overhead and no setup delay, and it never confirms or reorders anything. That makes it the right transport for real-time voice and video, online games, and quick request-and-reply lookups, where a late packet is worse than a missing one.
Trap Assuming UDP guarantees ordered, reliable delivery; it has no sequence numbers and no acknowledgments.
15 questions test this
- Which of the following correctly describes UDP as a transport-layer protocol?
- An organization is deploying VoIP phones and needs to minimize audio delay during calls. Which of the following transport-layer protocols…
- A junior technician asks why UDP is called a connectionless protocol. Which of the following best describes UDP's connectionless behavior?
- A company is deploying a VoIP phone system across its offices. Which of the following best explains why UDP is preferred over TCP for…
- A company is deploying a new VoIP telephone system. Which of the following protocols is best suited to carry real-time voice traffic with…
- A company is deploying a VoIP phone system and needs to select a transport-layer protocol for voice traffic. Which of the following is the…
- A technician analyzes network traffic and observes that standard DNS name resolution queries on port 53 complete quickly with minimal…
- A company is deploying a VoIP phone system and needs to minimize latency for real-time voice calls. Which of the following correctly…
- A company is deploying a VoIP phone system in its office. Which of the following BEST explains why UDP is the preferred transport protocol…
- A technician captures standard DNS name resolution queries on the network. Which of the following transport protocols are these queries…
- Which of the following accurately describes a characteristic of UDP?
- A company is deploying a VoIP phone system. Which of the following transport protocols is most appropriate for carrying the real-time voice…
- A company is deploying a VoIP phone system for internal communications. Which of the following BEST describes why a particular transport…
- A company is deploying a VoIP phone system across its offices. Which of the following best explains why UDP is preferred over TCP for…
- Which of the following characteristics of UDP makes it preferred for VoIP traffic?
- TCP opens a session with the three-way handshake
Before any TCP data flows, the client sends a SYN, the server replies SYN-ACK, and the client answers ACK, which establishes the connection. Only after that exchange does the sequenced, acknowledged data transfer begin.
8 questions test this
- A technician is reviewing a packet capture and sees a TCP connection being established between a client and a web server. Which of the…
- A technician reviewing a network capture observes a SYN, SYN-ACK, ACK exchange between two hosts before any data is transferred. Which of…
- A technician captures network traffic and observes a sequence of SYN, SYN-ACK, and ACK packets exchanged between two hosts before data…
- Which of the following correctly describes the sequence TCP uses to establish a connection between two hosts?
- Which of the following describes how TCP establishes a connection between two hosts?
- Which of the following describes the correct sequence of the TCP three-way handshake?
- A technician is analyzing a packet capture and observes the first three packets exchanged when a client connects to a web server. Which of…
- Which of the following best describes why TCP is classified as a connection-oriented protocol?
- DNS runs on both UDP 53 and TCP 53
Ordinary name-to-IP lookups use UDP 53 for a fast single exchange, but DNS switches to TCP 53 for zone transfers and for responses too large to fit one UDP datagram. A single protocol using both transports is exactly the kind of detail the exam probes.
Trap Answering 'UDP only' for a DNS zone transfer; oversized transfers use TCP 53.
11 questions test this
- A network administrator is configuring firewall rules for a DNS server. Which of the following explains why port 53 must allow both TCP and…
- Which of the following transport-layer protocols does DNS primarily use for standard name resolution queries?
- A network administrator observes DNS traffic on port 53 using both TCP and UDP. Which of the following best explains this behavior?
- A technician is configuring a firewall and needs to allow traffic so that workstations can resolve hostnames to IP addresses. Which of the…
- A firewall administrator needs to ensure that both standard name resolution queries and DNS zone transfers function correctly. Which of the…
- A technician analyzes network traffic and observes that standard DNS name resolution queries on port 53 complete quickly with minimal…
- A network administrator observes DNS traffic using TCP on port 53 between two DNS servers. Which of the following operations is most likely…
- A network technician observes that standard DNS lookups from client workstations use a different transport protocol than large DNS zone…
- A technician is configuring firewall rules for a DNS server on port 53. Which of the following correctly describes how DNS uses…
- A technician captures standard DNS name resolution queries on the network. Which of the following transport protocols are these queries…
- A network administrator is configuring firewall rules for a DNS server that handles standard name resolution queries and zone transfers to…
- SSH on TCP 22 is the encrypted replacement for Telnet on TCP 23
SSH gives an encrypted remote shell on port 22, while Telnet on port 23 sends everything, including the login, in cleartext. Any remote-administration question that mentions security wants SSH, not Telnet.
- RDP uses TCP 3389 for a graphical Windows remote desktop
RDP carries a full graphical Windows session over TCP 3389. Because it has a long brute-force and worm history, it should never be exposed raw to the internet; reach it through a VPN or a jump host.
Trap Exposing RDP 3389 directly to the internet instead of tunneling it through a VPN or jump host.
- SMB uses TCP 445; the legacy NetBIOS path was 137-139
Modern Windows file and printer sharing uses direct-host SMB on TCP 445, while ports 137-139 are the older NetBIOS path. Like RDP, SMB 445 has a wormable history and should not face the internet.
Trap Citing port 139 for current SMB; direct-host SMB uses TCP 445, and 137-139 is the legacy NetBIOS range.
- HTTP is TCP 80; HTTPS is TCP 443
Web traffic is cleartext HTTP on port 80 and TLS-encrypted HTTPS on port 443. The encrypted version is the same web protocol on a different port, so securing a site swaps 80 for 443.
- FTP uses TCP 20 and 21: 21 controls the session, 20 carries data
FTP opens a control channel on port 21 and moves file data on port 20, and both channels are cleartext. Knowing which port is control versus data is a common exam detail.
- SMTP relays on TCP 25; authenticated clients submit on 587
Server-to-server mail relay uses SMTP on port 25, but an authenticated mail client submits outgoing mail on port 587, commonly upgraded with STARTTLS. Providers often block outbound 25 from clients to fight spam.
Trap Configuring a mail client to send on port 25; authenticated submission uses 587 and many ISPs block outbound 25.
- POP3 (110) downloads and deletes mail; IMAP (143) keeps it synced on the server
POP3 on port 110 pulls messages down and removes them from the server, while IMAP on port 143 keeps the mailbox synchronized so the same mail appears on every device. Choose IMAP when a user reads mail from more than one device.
Trap Choosing POP3 for a user who reads mail on several devices; POP3 removes messages from the server, IMAP keeps them synced.
- DHCP uses UDP with the server on 67 and the client on 68
The DHCP client (port 68) broadcasts a DISCOVER because it has no address yet, and the server (port 67) answers, following the DORA sequence of Discover, Offer, Request, Acknowledge. Both ports are UDP.
Trap Swapping the DHCP ports; the server listens on UDP 67 (bootps) and the client on UDP 68 (bootpc).
3 questions test this
- A technician is configuring firewall rules on a SOHO router to allow client devices to automatically receive IP address configurations from…
- Several new workstations on a SOHO network fail to receive IP address configurations automatically when connected. Which of the following…
- Which of the following protocols automatically provides IP addressing configuration to network clients using UDP ports 67 and 68?
- SNMP polls agents on UDP 161 and receives traps on UDP 162
An SNMP manager polls agents for status on port 161, and agents push unsolicited alerts, called traps, to the manager on port 162. Both run over UDP.
Trap Expecting an SNMP trap to arrive on 161; scheduled polls use 161, but agent traps arrive on 162.
4 questions test this
- A network administrator needs to remotely check CPU utilization, interface errors, and uptime on managed network switches. Which of the…
- A network administrator needs to remotely collect data on interface errors and bandwidth usage from managed switches across the network.…
- A network administrator uses a management application to poll switch and router interfaces for bandwidth utilization and device status.…
- Which of the following protocols uses UDP port 161 to allow administrators to query and monitor the performance of network switches and…
- LDAP is TCP 389; the TLS version LDAPS is TCP 636
Directory queries, such as against Active Directory, run cleartext LDAP on port 389 and TLS-encrypted LDAPS on port 636. The secure variant moves to its own port like the other swaps.
5 questions test this
- A company stores user account information in a centralized directory that workstations query during the login process. Which of the…
- A network administrator needs to enable an application to authenticate users by querying a centralized directory for account information.…
- A technician is troubleshooting a network application that cannot query the centralized directory for user authentication. A firewall log…
- A company needs to allow a web application to query user account information from a centralized directory service. Which of the following…
- An organization stores user accounts, group memberships, and contact records in a centralized directory that applications query for…
- SFTP is an SSH subsystem on port 22, not FTP-over-TLS
SFTP is the file-transfer subsystem of SSH and runs on port 22, while FTPS is FTP wrapped in TLS. They secure file transfer by different mechanisms, so treating SFTP as FTP-over-TLS is wrong.
Trap Treating SFTP as FTP-over-TLS; SFTP runs inside SSH on port 22, and FTPS is the TLS-wrapped form of FTP.
- Secure mail retrieval ports: POP3S 995 and IMAPS 993
The TLS versions of the mailbox protocols each claim their own port: POP3S on 995 and IMAPS on 993. They pair with the cleartext POP3 110 and IMAP 143.
- 802.11 generations map to Wi-Fi 4, 5, and 6
The Wi-Fi Alliance renamed the recent 802.11 standards: 802.11n is Wi-Fi 4, 802.11ac is Wi-Fi 5, and 802.11ax is Wi-Fi 6. Wi-Fi 6E is the variant of Wi-Fi 6 extended into the 6 GHz band.
- 802.11ac (Wi-Fi 5) operates only in the 5 GHz band
Wi-Fi 5 (802.11ac) transmits only in the 5 GHz band, unlike 802.11n, which spans 2.4 and 5 GHz, and 802.11ax, which can use 2.4, 5, and 6 GHz. Dual-band Wi-Fi 5 gear still reaches a 2.4 GHz network, but through its 802.11n radio, since 802.11ac has no 2.4 GHz mode.
Trap Assuming 802.11ac itself runs on 2.4 GHz; the ac amendment is 5 GHz only, and a dual-band device falls back to 802.11n for 2.4 GHz.
- Only Wi-Fi 6E and later can use the 6 GHz band
The 6 GHz band is reachable only by Wi-Fi 6E (the 6 GHz extension of 802.11ax) and newer gear. A plain Wi-Fi 6 device without 6E stays on the 2.4 and 5 GHz bands.
Trap Assuming any Wi-Fi 6 device reaches 6 GHz; only the 6E variant and later use the 6 GHz band.
- In 2.4 GHz only channels 1, 6, and 11 do not overlap
The 2.4 GHz channels overlap, so in North America access points should sit on channel 1, 6, or 11 at 20 MHz width. Any other choice causes adjacent-channel interference, and two APs on the same channel cause co-channel interference.
Trap Spacing access points on channels 1, 5, and 9; only 1, 6, and 11 are non-overlapping in 2.4 GHz.
10 questions test this
- A technician uses a Wi-Fi analyzer in an office where users report slow wireless speeds. The analyzer shows the office access point on…
- A technician uses a Wi-Fi analyzer in a densely populated apartment complex and observes 15 networks broadcasting on the 2.4 GHz band.…
- A Wi-Fi analyzer shows that all three non-overlapping channels in the 2.4 GHz band are congested with neighboring access points in a SOHO…
- A technician uses a Wi-Fi analyzer at a small office and notices the company's 2.4 GHz router is set to channel 4 while a neighbor's access…
- A technician runs a Wi-Fi analyzer in a small office suite and observes that the company access point on channel 1 has signal overlap with…
- A technician runs a Wi-Fi analyzer and discovers that five neighboring access points are broadcasting on channel 6, the same channel used…
- A technician uses a Wi-Fi analyzer at a user's workstation and sees the office network on channel 6 at -72 dBm and two neighboring networks…
- A technician uses a Wi-Fi analyzer in a small office and observes that nearby networks are heavily utilizing channels 1 and 11 on the 2.4…
- A technician uses a Wi-Fi analyzer to troubleshoot slow wireless performance at a SOHO. The analyzer shows the office router broadcasting…
- A technician uses a Wi-Fi analyzer and detects the following 2.4 GHz networks near a client's office: Network A on channel 1 at -45 dBm,…
- 2.4 GHz reaches farthest; 5 and 6 GHz are faster at shorter range
The 2.4 GHz band penetrates walls best and reaches farthest but is the slowest and most congested. The 5 GHz band is much faster with more channels at shorter range, and 6 GHz is the widest and cleanest band but the shortest range.
4 questions test this
- A technician uses a Wi-Fi analyzer in a crowded office building and discovers that all three non-overlapping 2.4 GHz channels are heavily…
- A technician is troubleshooting slow wireless performance in a crowded apartment complex. A Wi-Fi analyzer scan reveals 15 networks in the…
- A technician uses a Wi-Fi analyzer and discovers that 12 neighboring access points are broadcasting in the 2.4 GHz band while the 5 GHz…
- A technician uses a Wi-Fi analyzer in a client's apartment and discovers 14 SSIDs on the 2.4 GHz band but only 2 SSIDs on the 5 GHz band.…
- NFC works only at a touch, a few centimeters
NFC operates at 13.56 MHz over just a few centimeters, and that tiny range is itself the security model. It drives tap-to-pay, transit cards, and tap-to-pair, and it is a short-range relative of RFID.
Trap Choosing Bluetooth for a tap-to-pay terminal; contactless payment uses NFC at a few centimeters.
- Bluetooth links peripherals across a room, about 10 meters
Bluetooth forms a personal-area network after a pairing step and carries keyboards, mice, headsets, speakers, and phone tethering, typically to about 10 meters for common class 2 radios. It is the room-scale wireless, one step up from NFC's touch range.
- Passive RFID tags have no battery; active tags do
A passive RFID tag draws power from the reader's field and works only at very short range, while an active tag carries its own battery and reaches much farther. RFID drives inventory, asset tracking, and badge access.
Trap Assuming every RFID tag is battery-powered; passive tags are energized by the reader's radio field.
- Long-range fixed wireless bridges point-to-point links across miles
Fixed wireless uses directional antennas aimed line-of-sight between two fixed points, on licensed or unlicensed spectrum, to connect buildings or rural sites where running cable is impractical. It is the technology for a distance far beyond what Wi-Fi covers.
- NTP on UDP 123 keeps clocks in sync for time-sensitive services
NTP (Network Time Protocol) runs on UDP port 123 and synchronizes system clocks across networked devices. Services that depend on close time agreement, above all Kerberos authentication and correlated log timestamps, begin failing when server clocks drift apart, so a set of hosts showing different times points straight at NTP.
Trap Treating a Kerberos or logon failure as a broken authentication server when clock skew across the hosts is the real cause.
5 questions test this
- Several servers on a network display different system times, causing failures with time-sensitive authentication services. Which of the…
- A network administrator notices that event logs across multiple servers display different timestamps for the same incident. Which of the…
- Several workstations on a network are displaying incorrect system times, and users are experiencing Kerberos authentication failures…
- After a building-wide power outage, a technician discovers that log timestamps across multiple network servers are inconsistent, causing…
- After a building-wide power outage, a technician discovers that event log timestamps across multiple servers differ by several hours. Which…
- TCP paces a sender with the sliding window the receiver advertises
TCP does flow control with a sliding window: the receiver advertises a window size that says how much unacknowledged data it can still buffer, and the sender never sends past it. This is what makes a fast sender slow down for a slow or congested receiver instead of overrunning its buffer, and it is separate from the connection setup and the acknowledge-and-retransmit that provide reliability.
Trap Crediting the three-way handshake, which only opens the session, with pacing the ongoing data flow.
6 questions test this
- Which of the following mechanisms does TCP use to manage the rate of data transmission between a sender and receiver?
- A technician observes that a TCP file transfer adjusts its transmission speed during periods of network congestion. Which of the following…
- A technician discovers that a TCP sender is transmitting data faster than the receiver can process it. Which of the following TCP features…
- During a large file transfer over TCP, the receiving host advertises the amount of data it can accept at one time. Which of the following…
- A technician is explaining how TCP prevents a fast sender from overwhelming a slow receiver with data. Which of the following TCP…
- A technician notices that a large file download over TCP automatically reduces its sending rate when the receiving computer's buffer is…
- Wi-Fi 6 (802.11ax) is built for high-density environments
802.11ax, marketed as Wi-Fi 6, was designed to raise efficiency where many clients share the air, such as stadiums, convention centers, and crowded offices. It does this with OFDMA and enhanced MU-MIMO, which let one transmission serve several stations at once and lift the average throughput per client rather than only the peak speed.
Trap Choosing Wi-Fi 5 (802.11ac) for its raw peak speed when the real problem is many simultaneous clients.
4 questions test this
- A company is upgrading its wireless infrastructure in a crowded office building with hundreds of connected devices. Which of the following…
- A network administrator is deploying wireless access points in a convention center where hundreds of users will connect simultaneously.…
- A convention center with thousands of simultaneous wireless users needs a Wi-Fi standard designed to improve efficiency in dense…
- A convention center needs to support thousands of simultaneous Wi-Fi connections efficiently. Which of the following wireless standards was…
SOHO Networks
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Networking Tools
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Hardware
RAM, CPUs, and Storage
Read full chapterCheat sheet
Sharp facts the exam loves — scan these before test day.
- Each DDR generation fits only its own slot
DDR3, DDR4, and DDR5 modules are keyed with the notch in a different spot, so a stick physically will not seat in a slot built for another generation, and the memory controller supports only one generation. DDR4 and DDR5 DIMMs even share a 288-pin edge, yet the notch position still differs, so they are not interchangeable. Confirm the board's generation before ordering memory, because the fastest DDR5 kit is useless in a DDR4 board.
Trap Assuming DDR4 and DDR5 interchange because both are 288-pin DIMMs; the key notch sits in a different position and the controller accepts only one generation.
- DDR voltage drops as the generation climbs
Standard operating voltage falls each generation: DDR3 runs at 1.5 V (DDR3L at 1.35 V), DDR4 at 1.2 V, and DDR5 at 1.1 V, which is part of how newer memory raises bandwidth while holding power in check. The data rate moves the other way, from roughly 800 to 2133 MT/s (mega-transfers per second) on DDR3 up to 4800 MT/s and beyond on DDR5.
- DIMM is for desktops, SO-DIMM is for laptops
A full-size DIMM (dual inline memory module) goes in desktop and server boards, while the shorter SO-DIMM (small outline DIMM) is the laptop and small-form-factor version of the same generation. The two are not cross-compatible in a slot, so a laptop upgrade needs SO-DIMM of the correct DDR generation. All-in-one PCs and mini PCs often use SO-DIMM to save space.
Trap Putting a desktop DIMM in a laptop; the laptop slot only accepts the shorter SO-DIMM even when the DDR generation matches.
- Dual channel needs matched modules in the paired slots
Installing one identical module in each memory channel lets the controller run dual channel, which roughly doubles memory bandwidth over a single stick; capable boards extend this to quad channel with four modules. The slots for each channel are color-coded or named in the manual, often the second slot of each channel, and the modules should match in size and speed. A single stick, or two mismatched sticks, drops the system back toward single-channel bandwidth.
Trap Putting both sticks in one channel's two slots; that leaves the array single-channel, so use one slot from each channel per the board's color coding.
- ECC memory corrects single-bit errors but needs platform support
ECC (error-correcting code) memory carries an extra chip that detects and fixes single-bit errors in real time, which is why servers and workstations that cannot tolerate silent corruption use it. It only works when the CPU and motherboard support ECC, so dropping an ECC module into a typical consumer desktop gives you no error correction. Mainstream desktops and laptops run non-ECC memory, trading that protection for lower cost.
Trap Assuming DDR5 on-die ECC turns every DDR5 module into ECC memory; on-die ECC only protects the chip's cells internally and does not report or correct errors to the system the way a true ECC DIMM does.
- Mixed memory runs at the slowest module's rating
When you mix modules of different speeds, the memory controller clocks the whole set to the slowest stick's supported rate, and mixing sizes or timings can force single-channel operation. For predictable dual-channel performance, install a matched kit that was sold and tested together. Faster memory in the mix does not raise the baseline; it just runs slower to stay compatible.
- LGA puts pins on the socket, PGA on the chip
An LGA (land grid array) socket holds the delicate pins while the CPU shows flat contact pads, so Intel mainstream sockets and AMD's newer AM5 are LGA. A PGA (pin grid array) chip carries the pins itself and drops into holes in the socket, as on older AMD sockets like AM4. The distinction decides where a bent pin lives and how carefully you handle each part during install.
Trap Treating the CPU as the damaged part when pins bend on an LGA system; there the pins are in the motherboard socket, not on the chip, so the board is what is bent.
8 questions test this
- A technician notices that a new AMD Ryzen 7000 series processor has flat contact pads on its underside rather than pins. Which of the…
- A technician is preparing to install a Ryzen 7000 series processor on a new AM5 motherboard. When inspecting the CPU socket, which of the…
- After replacing the CPU in a desktop computer, a technician notices the system fails to POST. Upon inspection, several bent pins are found…
- A technician is upgrading a desktop from an AMD AM4 platform to AM5. Which of the following describes a key physical difference the…
- A technician accidentally drops a small tool onto the open LGA 1700 CPU socket on a new motherboard. Which of the following socket…
- A technician is upgrading a desktop from an AMD AM4 platform to AMD AM5. Which of the following correctly describes the AM5 socket design?
- A technician is upgrading a workstation from an AMD AM4 motherboard to AM5. Which of the following describes a key physical difference…
- A technician is installing a processor on an AMD AM5 motherboard. Which of the following describes the physical interface between the CPU…
- Thermal paste goes on thin, and too much insulates
Thermal paste fills the microscopic gaps between the CPU's heat spreader and the cooler base so heat can cross into the cooler; a thin, even layer is the goal. Too much paste acts as an insulator and can ooze onto the socket, while none at all leaves an air gap that causes overheating and thermal shutdowns. Reseating a cooler means cleaning off the old paste and applying fresh compound.
Trap Applying a thick blob of paste to be safe; excess compound insulates and can spill onto pins, so a thin even layer transfers heat better.
10 questions test this
- A technician is reapplying thermal paste to a desktop CPU after removing the cooler for maintenance. Which of the following should the…
- After installing a new CPU and cooler, a technician powers on the computer. The system begins to boot but shuts down within a few seconds.…
- A technician is replacing a CPU air cooler on a desktop. After removing the old heatsink, the technician observes dried thermal compound on…
- A technician is replacing a CPU cooler on a desktop computer. After removing the old cooler, which of the following should the technician…
- A technician applies thermal paste while installing a CPU cooler on a new desktop build. Which of the following best describes the primary…
- A technician needs to apply thermal compound before installing a CPU air cooler. Which of the following describes the correct application…
- What is the primary purpose of applying thermal compound between a CPU and its heatsink?
- A technician removes a CPU air cooler to inspect a processor and notices residual thermal paste on both surfaces. Before reinstalling the…
- A technician is applying thermal compound between a CPU and a heatsink during cooler installation. Which of the following best describes…
- A technician is preparing to install a CPU cooler on a newly seated desktop processor. Which of the following describes the correct thermal…
- A matching socket still needs chipset and BIOS support
A CPU has to fit the socket and be supported by the motherboard's chipset and firmware, because a newer chip can share a socket with older boards yet need a BIOS update before it will POST. Check the board maker's CPU support list, not just the socket name, before buying. A supported socket with stale firmware can leave the system dead until you flash the BIOS with a compatible chip.
Trap Assuming a socket match alone guarantees a CPU works; the same socket can need a BIOS update first, so an unsupported firmware version will not boot the chip.
- Align the CPU by its corner marker and never force it
A CPU seats only one way, marked by a small triangle or notch that lines up with the matching mark on the socket, and it should settle in under its own weight with zero force. Forcing a misaligned chip bends pins, whether on the chip (PGA) or in the socket (LGA). Lower the retention arm to lock it once it sits flat.
- 7200 RPM drives are faster; 5400 RPM run cooler and quieter
A hard disk drive's spindle speed sets its baseline performance, so a 7200 RPM drive reads and writes faster than a 5400 RPM drive of the same design. The 5400 RPM class runs cooler, quieter, and on less power, which is why laptops and bulk storage favor it, while 7200 RPM suits performance desktops. Spindle speed matters only for HDDs; an SSD has no platters to spin.
Trap Treating RPM as an SSD spec; solid-state drives have no spindle, so RPM is meaningless for them.
- SSDs have no moving parts, so they beat HDDs on speed and shock
A solid-state drive stores data in flash memory with no platters or heads, giving far lower latency, faster boot and load times, silent operation, and much better shock resistance than a hard disk drive. An HDD still wins on cost per terabyte, which is why bulk and archival storage often stays on spinning disks. A common upgrade is to boot from an SSD and keep an HDD for large files.
- SATA III caps a drive near 600 MB/s no matter the media
The SATA (Serial ATA) III bus runs at 6 Gb/s, which works out to roughly 550 to 600 MB/s of real throughput, and that ceiling applies whether the drive is a hard disk or a SATA SSD. A fast SATA SSD saturates the bus, so the only way past the limit is a different interface, which is exactly what NVMe over PCIe provides.
- NVMe rides PCIe lanes to reach multi-gigabyte speeds
NVMe (Non-Volatile Memory Express) is a protocol that connects the SSD straight to the CPU over PCIe (PCI Express) lanes instead of the SATA bus, so a typical NVMe drive reaches 3,500 MB/s and up, several times a SATA SSD's ceiling. The trade is that NVMe needs an M.2 slot (or add-in card) wired for PCIe. For boot disks and heavy workloads, NVMe is the clear performance pick.
Trap Assuming any M.2 slot delivers NVMe speed; a slot wired only for SATA will not run an NVMe drive at all, so the slot has to provide PCIe lanes.
- An M.2 drive can be SATA or NVMe, so check the slot
M.2 is only a physical form factor, so an M.2 stick may speak either SATA or NVMe, and the two are not automatically interchangeable in a given slot. A slot's keying (B-key, M-key, or B+M) and the board manual tell you which interfaces it accepts. Match the drive's protocol to what the slot supports, or the drive runs at the wrong speed or not at all.
Trap Assuming every M.2 drive is NVMe; M.2 is just the shape, and a SATA M.2 drive behaves like a SATA drive despite the M.2 form factor.
- Know the physical form factors: 3.5in, 2.5in, and M.2
Desktop hard drives use the 3.5-inch form factor, while 2.5-inch bays hold laptop hard drives and SATA SSDs, and M.2 is the small gumstick card that mounts flat on the board (commonly the 2280 size, 22 mm by 80 mm). Form factor is about physical fit and mounting, separate from the SATA-versus-NVMe interface question. A 2.5-inch drive is always SATA; only M.2 or an add-in card carries NVMe.
- RAID 0 stripes for speed with zero redundancy
RAID 0 splits data across two or more drives (striping) to add their speed and capacity, but it stores no parity or mirror, so losing any single drive destroys the entire array. It fits scratch space and workloads that value throughput over safety. Because a single failure wipes everything, RAID 0 actually increases the chance of data loss versus one drive.
Trap Treating RAID 0 as safe because it spans multiple drives; it has no redundancy at all, and one failed drive loses the whole array.
4 questions test this
- A video editor needs the fastest possible disk read and write speeds on a workstation and maintains verified backups on a separate NAS.…
- A graphic designer has two drives configured in RAID 0 on a workstation for maximum disk performance. One of the drives fails. Which of the…
- A video editor creates a two-drive RAID 0 array using the motherboard RAID BIOS utility for maximum storage performance. After several…
- A video editor needs maximum disk throughput for editing large project files and accepts the risk of data loss. The workstation has two…
- RAID 1 mirrors two drives for redundancy
RAID 1 writes the same data to two drives (mirroring), so the array keeps running if one drive fails and you rebuild by copying from the survivor. The cost is capacity: usable space equals one drive, or 50 percent of the raw total. It is the simplest way to protect a two-drive system against a single disk failure.
- RAID 5 stripes with distributed parity across three or more drives
RAID 5 stripes data with parity spread across at least three drives, so it survives one drive failure and rebuilds the lost data from parity, while usable capacity is the total minus one drive's worth. It balances redundancy and space more efficiently than mirroring, which is why it is common for file servers. A second drive failing before the rebuild finishes loses the array.
Trap Assuming RAID 5 survives two simultaneous drive failures; it tolerates only one, and a second failure during rebuild loses the array.
11 questions test this
- A technician replaces a failed drive in a server's four-drive RAID 5 array that uses a hardware RAID controller. Which of the following…
- A file server with five drives configured in a RAID 5 array experiences a single drive failure. Which of the following best describes the…
- A technician is building a RAID 5 array using a hardware RAID controller with four 2TB drives. Which of the following represents the total…
- A technician needs to configure four identical 1TB drives in a workstation to provide fault tolerance while maximizing usable storage…
- A server administrator receives an alert that one drive in a four-drive RAID 5 array has failed. Which of the following best describes the…
- A server uses a five-disk RAID 5 array. One drive fails and the array operates in a degraded state. A second drive then fails before the…
- A technician hot-swaps a replacement drive into a server's hardware RAID 5 array after a single drive failure. Which of the following…
- A server running a five-drive RAID 5 array managed by a hardware RAID controller alerts the administrator that one drive has failed. The…
- A server's hardware RAID controller reports a degraded RAID 5 array caused by a single failed drive. The server remains operational. Which…
- A server uses a four-drive RAID 5 array managed by a hardware RAID controller. One of the drives fails while the server is running. Which…
- A technician replaces a failed drive in a RAID 5 array managed by a hardware RAID controller. Which of the following describes what occurs…
- RAID 10 mirrors then stripes for speed plus redundancy
RAID 10 stripes across mirrored pairs, needing at least four drives, so it delivers both the speed of striping and the fault tolerance of mirroring, tolerating a drive failure in each mirror. Usable capacity is 50 percent of the raw total, the same overhead as RAID 1. It is the go-to when a workload needs high performance and redundancy and can afford the drives.
3 questions test this
- A technician needs to configure a storage solution that provides data redundancy through mirroring and improved performance through…
- A server has four drives configured as a RAID 10 array. Which of the following drive failure scenarios would result in complete data loss?
- A technician replaces a failed drive in a four-drive RAID 10 array connected to a hardware RAID controller. Which of the following…
- RAID protects against drive failure, not deletion or corruption
RAID keeps a system available when a disk fails, but it is not a backup, because deletions, corruption, ransomware, and controller faults propagate across the array immediately. You still need separate backups to recover from those events. Treating RAID as your only copy of the data is a classic mistake the exam probes.
Trap Relying on a redundant RAID array as the backup; RAID does not protect against deletion, corruption, or malware, which hit every drive at once.
- Tighten a CPU cooler gradually in a diagonal cross pattern
Secure a CPU cooler by turning its retention screws only a few turns each in a diagonal cross (X) pattern, cycling around until all are snug, so mounting pressure lands evenly across the CPU heat spreader for uniform thermal-paste contact. Fully tightening one corner first tilts the cooler and leaves poor contact. A cooler that is loose or unevenly mounted loses that contact and can overheat and shut the system down within minutes of boot.
Trap Fully tightening one corner screw before the others, which tilts the cooler off the die.
5 questions test this
- When mounting a CPU cooler that uses four retention screws, which of the following techniques should the technician use to secure the…
- After applying thermal paste to a newly installed processor, a technician is mounting a tower air cooler. Which of the following is the…
- A technician is securing a heatsink and fan assembly onto a newly installed CPU. Which of the following describes the correct procedure for…
- A technician has applied thermal paste and positioned the CPU cooler on a desktop processor. Which of the following is the proper technique…
- A technician installs a new CPU, applies thermal paste, and mounts the cooler in a desktop computer. On startup, the system powers off…
- Set the UEFI SATA mode to RAID for an array, AHCI for a single drive
The motherboard's onboard RAID utility only appears if you first set the SATA controller mode to RAID in UEFI/BIOS; left on AHCI or IDE, the RAID option ROM never loads and no array can be built during POST. For a normal single SATA drive or SSD, AHCI is the correct mode, enabling native command queuing and hot-plug for the best performance. The mode is a firmware setting, not something the drive or the operating system selects on its own.
Trap Leaving the SATA mode on AHCI or IDE and expecting the RAID utility to appear at POST.
4 questions test this
- A technician is building a workstation and needs to configure a RAID array using the motherboard's integrated RAID capability. After…
- A technician is setting up two drives in RAID 1 using the motherboard's built-in RAID capability on a new workstation. After physically…
- A technician installs a new SATA SSD as the primary boot drive in a desktop and needs to configure the BIOS/UEFI for optimal drive…
- A technician is building a workstation and needs to create a RAID array using the motherboard's built-in controller. The SATA drives are…
Cables and Connectors
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Peripheral Devices
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Motherboards and Power
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Virtualization and Cloud Computing
Virtualization Concepts
Read full chapterCheat sheet
Sharp facts the exam loves — scan these before test day.
- A virtual machine is a full computer defined in software
A virtual machine (VM) has its own virtual CPU, memory, disk, and network adapter and runs its own guest operating system, which behaves as if it owned real hardware. The physical machine it runs on is the host, and one host can run many VMs at the same time. Because the VM is software, you can copy, snapshot, move, or delete a whole computer as a set of files.
A hypervisor, also called the virtual machine monitor, creates VMs, divides one host's CPU, RAM, storage, and network among them, and keeps each VM isolated so a fault or infection in one cannot reach the host or its neighbors. NIST frames it as the component that manages the guest operating systems and controls the flow of instructions between the guests and the physical hardware. Sharing and isolating are its two jobs, and most exam scenarios reward matching a requirement to one of them.
- Type 1 hypervisors run on bare metal for servers
A Type 1 (bare-metal) hypervisor installs directly on the hardware with no host operating system beneath it, so it effectively is the host's OS. With no extra layer to cross it has lower overhead and a smaller attack surface, which is why data centers and servers use it. VMware ESXi and Microsoft Hyper-V are the standard examples.
Trap Assuming a Type 1 hypervisor needs Windows or Linux installed underneath it first; it replaces that general-purpose OS rather than running on top of one.
12 questions test this
- Which of the following is a key architectural characteristic of a Type 1 hypervisor?
- A technician is comparing two virtualization approaches. Approach A loads directly onto server hardware to maximize VM performance, while…
- A cloud hosting company rents virtual machines to many customers and needs each physical server to boot straight into the virtualization…
- An organization needs a virtualization solution for its data center that provides the strongest VM isolation and direct hardware access.…
- An enterprise data center is standardizing its hosts so that the virtualization layer boots directly from the server hardware and manages…
- A managed service provider is building a data center and wants to consolidate dozens of aging physical servers onto a few powerful hosts,…
- A company is deploying a dedicated rack server whose only purpose is to host multiple production virtual machines. The virtualization…
- Which of the following explains why a Type 1 hypervisor generally provides better virtual machine performance than a Type 2 hypervisor?
- A data center administrator needs to deploy a hypervisor to host production virtual machines with maximum performance and security. Which…
- An organization is virtualizing its data center servers to improve resource efficiency. Which of the following hypervisor types should be…
- Which of the following is a security advantage of deploying a Type 1 hypervisor instead of a Type 2 hypervisor?
- Which of the following is an example of a Type 1 bare-metal hypervisor?
- Type 2 hypervisors run as an app on a desktop OS
A Type 2 (hosted) hypervisor runs as an ordinary application on top of an operating system you already booted, such as Windows or macOS. That makes it the easy way to run a second OS on a laptop or workstation, at the cost of an extra host-OS layer between the VMs and the hardware. VMware Workstation, Oracle VirtualBox, and Parallels Desktop are Type 2.
Trap Assuming every VMware product is the same type; VMware Workstation is Type 2 (hosted) while VMware ESXi is Type 1 (bare-metal).
12 questions test this
- A help desk technician needs to occasionally launch a virtual machine running an older operating system inside their everyday Windows 11…
- An instructor wants to run several practice virtual machines on their personal MacBook for a classroom demonstration while keeping macOS…
- A software developer needs to test applications on multiple operating systems using a workstation that already runs Windows. Which of the…
- A software developer needs to spin up a temporary virtual machine on their iMac to reproduce a bug, while keeping their existing macOS…
- A developer needs to run a Linux virtual machine alongside Windows on a single laptop for software testing. Which of the following is the…
- A technician is planning a Type 2 hypervisor deployment for client-side virtualization. Which of the following is a requirement specific to…
- A technician notices slower VM performance on a Type 2 hypervisor compared to a Type 1 hypervisor running on identical hardware. Which of…
- A technician is setting up client-side virtualization on a user's desktop PC. Which of the following is an example of a Type 2 hypervisor?
- A technician installs Oracle VirtualBox on a Windows 11 workstation to create virtual machines for testing. Which of the following…
- A technician notices that virtual machines on a Type 2 hypervisor perform slower than those on a Type 1 hypervisor with identical hardware…
- A technician wants to run a single Linux virtual machine on their personal Windows 11 laptop so they can test software while still using…
- A developer needs to run virtual machines for software testing while continuing to use the same workstation for daily productivity tasks.…
- Hyper-V is a Type 1 hypervisor even on a desktop
Microsoft Hyper-V is a bare-metal (Type 1) hypervisor, and enabling it on Windows 11 does not make it Type 2. When the Hyper-V feature turns on, Windows itself is shifted to run on top of the hypervisor, so the hypervisor still sits directly on the hardware. Do not classify a hypervisor by whether you started it from a desktop.
Trap Calling client Hyper-V Type 2 because you enabled it from within Windows; the hypervisor runs beneath Windows, which makes it Type 1.
- Client Hyper-V needs a 64-bit SLAT CPU and at least 4 GB RAM
Microsoft's client Hyper-V requires a 64-bit processor with SLAT (second-level address translation), VM Monitor Mode extensions, hardware-enforced DEP (the Intel XD bit or the AMD NX bit), and at least 4 GB of RAM, plus virtualization enabled in firmware. SLAT lets the hardware translate a guest's memory addresses instead of the hypervisor, which cuts overhead. Running systeminfo on Windows reports whether each requirement is met.
- Size the host for itself plus every VM running at once
Each running VM reserves a real slice of the host's CPU, memory, disk, and network, so a host must cover its own needs plus the sum of what its VMs consume at the same time. Memory is usually the first ceiling: four VMs assigned 4 GB each want roughly 16 GB before the host's own overhead. Undersize any resource and VMs either fail to start or crawl as they contend for it.
Trap Planning a host around a single VM's requirements; the host must carry all concurrent VMs plus its own overhead.
- Oversubscribing resources works only until VMs peak together
A hypervisor can oversubscribe, allocating VMs more virtual CPU or memory than the host physically has, on the bet that not all of them peak at once. It breaks when they do, so leave headroom for the host and keep total VM demand under the host's real capacity. This is a scheduling gamble, not free capacity.
Trap Assigning nearly all of the host's RAM to VMs; starving the host's own operating system slows every guest at once.
- Use a VM to run legacy or cross-platform software
When an application needs an operating system your hardware does not run, put it in a VM with the OS it requires, such as an old Windows release for a legacy app or Linux on a Windows host. This avoids buying and maintaining separate physical hardware for each platform. The VM's isolation also keeps an unsupported legacy OS off the rest of the machine.
- Snapshots make VMs ideal for test and development
A snapshot captures a VM's exact state so you can make risky changes and then roll straight back if they go wrong. That lets a test and development workflow build, break, and rebuild an environment that mirrors production without touching real systems. Reverting the snapshot or discarding the VM returns to a known-good state in seconds.
- A sandbox is a disposable, isolated place to run risky things
A sandbox is a throwaway isolated environment for safely running one untrusted app or file. Windows Sandbox is the built-in example: it isolates whatever you install from the host using hypervisor-based virtualization, and closing it deletes all software, files, and state, so every launch is a fresh, clean instance. It needs Windows Pro, Enterprise, or Education (not Home) and virtualization enabled in firmware.
Trap Reaching for a full persistent VM just to open one suspicious file; a sandbox discards everything on close with no cleanup, which a standing VM does not.
3 questions test this
- A technician receives a suspicious file and needs to analyze it without risking damage to the host system. Which of the following…
- Which of the following is a key characteristic of a sandbox environment that differentiates it from a standard virtual machine?
- A support technician must evaluate a suspicious software update before approving it for company-wide deployment and needs a disposable…
- Clone one VM image to give every trainee an identical lab
Because a VM is a set of files, you can clone one prepared image so every learner or tester gets the same environment and can reset it to a clean state on demand. That makes training rooms and QA labs consistent and cheap to rebuild. The same isolation means one student's mistake stays inside that student's VM.
- Consolidate many VMs on one host to save hardware and power
Resource efficiency is the core reason data centers virtualize: packing many VMs onto one capable host raises utilization and cuts hardware count, power draw, cooling, and rack space. A Type 1 hypervisor does this with the least overhead. The trade is that the shared host becomes a single point that must be sized and protected for all of its VMs.
- VM isolation contains a crash or malware to one guest
The isolation a hypervisor enforces is the security payoff: a bug, a bad patch, or malware in one VM stays inside that VM instead of spreading to the host or its neighbors. This is why untrusted or experimental work belongs in a VM. Isolation is a property of the virtualization boundary, not something the guest OS provides for itself.
- VM escape is the worst-case break of guest isolation
A VM escape is code inside a guest breaking out of its VM to reach the hypervisor or the other guests, which defeats the isolation the whole model depends on. It is the most serious virtualization flaw because it crosses the boundary that is supposed to contain each guest. Keeping the hypervisor patched and limiting what a VM can touch are the routine defenses.
Trap Confusing VM escape with resource exhaustion or VM sprawl; escape specifically means breaking out of a guest to reach the hypervisor or other guests.
- VMs on the same virtual switch are not automatically walled off
VMs reach the network through a virtual switch the hypervisor presents, mapped onto the host's physical adapter. Isolation of compute does not imply isolation of network: a VM sharing a virtual switch with production can talk to it unless you segment them. Put a VM on a separate switch or segment the network when it must stay off other traffic.
Trap Assuming a VM is network-isolated just because it is a separate machine; sharing a virtual switch with production leaves it reachable until you segment it.
Cloud Computing Models
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.
Hardware and Network Troubleshooting
Diagnosing Issues
Read full chapterCheat sheet
Sharp facts the exam loves — scan these before test day.
- Run the six troubleshooting steps in their fixed order
CompTIA's methodology is a fixed sequence: identify the problem, establish a theory of probable cause, test the theory to determine the cause, establish a plan of action and implement the solution, verify full system functionality and add preventive measures, then document the findings, actions, and outcomes. CompTIA publishes this methodology with the 220-1201 objectives as a competency standard and states that the methodology itself will not be tested, so learn the order as working practice; what is graded is reading a symptom back to its cause and naming the right next action.
Trap Jumping to a plan of action or a parts swap before the theory has actually been tested; testing the theory is its own step and comes first.
- In step one, gather information and back up before you change anything
Identifying the problem means interviewing the user, asking what changed, reproducing the symptom, and inquiring about recent environmental or infrastructure changes such as an office move or a power event. If a planned fix could put data at risk, back it up first, because a lost drive you could have imaged is a self-inflicted second problem.
Trap Reaching for a reimage, repartition, or drive swap before backing up data the repair could destroy.
- Question the obvious before you theorize an expensive failure
Step two starts with the cheap, likely causes and works up: a loose or unplugged cable, a wall switch, a disabled adapter, or the wrong monitor input before a dead motherboard or PSU. When the symptom is unfamiliar, external or internal research (vendor documentation, a beep-code table, a knowledge base) is a legitimate part of forming the theory, not an admission of defeat.
- An unconfirmed theory means form a new one or escalate, never repair
Testing the theory has two outcomes: confirmed sends you to a plan of action, and not confirmed sends you back to establish a new theory or to escalate to someone with more access or expertise. You never move from an unconfirmed theory straight to ordering or swapping a part.
Trap Continuing to swap parts by trial and error when a theory keeps failing, instead of escalating to someone with more access or expertise.
- A repair is not done until you verify full functionality and document
Step five verifies the original complaint is gone and nothing new broke, and where applicable adds preventive measures such as clearing dust, securing a loose cable, or scheduling a firmware update. Step six documents the findings, actions, and outcomes so the next technician starts ahead. Stopping after the part swap leaves the job formally incomplete.
- For a PC with no power at all, work the power path from the outside in
No fans and no lights is a power problem, not a POST problem, so trace the power path in order: wall outlet, surge strip, the PSU voltage switch and power switch, the 24-pin and CPU power connectors, and the front-panel power button header. Test those cheap causes before you condemn the power supply or the board.
Trap Assuming a dead motherboard when a flipped PSU switch, a dead outlet, or a loose power connector is the cheaper and likelier cause.
- No POST means re-seat RAM and GPU, clear CMOS, and read the codes
When a system powers on but never begins to boot, it is failing POST (power-on self-test, the firmware's start-up hardware check). Re-seat RAM and the GPU, clear CMOS, boot with minimal hardware, and match the beep or POST code to the motherboard or BIOS vendor's table to localize the failing component.
Trap Treating a no-POST machine as a no-power fault and replacing the PSU, when the system already powers on and the fault is downstream.
18 questions test this
- After installing a new graphics card, a technician powers on a desktop and hears one long beep followed by two short beeps. No image…
- A desktop PC that was previously working begins emitting repeating short beeps and fails to boot after a technician installed additional…
- After assembling a new desktop PC, a technician powers it on and observes that the DRAM diagnostic LED on the motherboard remains…
- A technician powers on a desktop computer and hears three short beeps repeating from the internal speaker during startup. The monitor…
- A technician is troubleshooting a newly built desktop PC that powers on but shows no display. The motherboard has four onboard diagnostic…
- A technician assembles a new desktop PC and powers it on for the first time. The system produces no display and no beep codes. The…
- After installing additional memory modules, a technician powers on a desktop and the fans spin and the LEDs light up, but the screen stays…
- A technician is troubleshooting a desktop that powers on but has no video output. The motherboard has diagnostic LEDs labeled CPU, DRAM,…
- A technician is troubleshooting a newly built PC that will not boot. The motherboard has four labeled debug LEDs for CPU, DRAM, VGA, and…
- After installing new RAM modules in a desktop, a technician powers on the system and hears continuous short beeps repeating in a loop. No…
- A technician is troubleshooting a desktop that powers on with spinning fans but produces no display output. The motherboard diagnostic LED…
- A technician is troubleshooting a desktop that fails to boot. The motherboard has four diagnostic LEDs labeled CPU, DRAM, VGA, and BOOT.…
- After installing a new graphics card, a technician powers on a desktop and the system produces repeating beep codes with no video on the…
- A technician is training a new employee on hardware troubleshooting. The new employee asks what happens when a computer is first powered…
- A technician installs new memory modules in a desktop PC and powers it on. The system produces repeating beep codes from the internal…
- A technician powers on a workstation and the system produces a beep code that the motherboard manual identifies as a memory initialization…
- A technician is troubleshooting a desktop that powers on but produces no display. The motherboard has four diagnostic LEDs labeled CPU,…
- A technician powers on a desktop PC and hears a continuous repeating pattern of short beeps from the internal speaker that does not stop.…
- A single boot beep is normal; a repeating pattern is a coded error
One short beep at boot is usually the normal, successful POST all-clear on most systems, while a repeating or patterned beep is a coded hardware error. The pattern's meaning is specific to the motherboard or BIOS/UEFI vendor, so look it up rather than guessing which component it names.
Trap Reading a single short boot beep as a fault; on most systems it is the normal signal that POST passed.
6 questions test this
- After replacing the motherboard in a desktop computer, a technician powers on the system and hears a single short beep from the internal…
- A desktop computer fails to boot and emits a pattern of beep codes from the internal speaker during startup. Which of the following should…
- A desktop computer emits a continuous repeating series of short beeps during startup and fails to complete POST. Which of the following is…
- A technician assembles a new desktop PC and powers it on for the first time. The system produces a single short beep and the BIOS splash…
- A technician builds a new desktop computer and powers it on for the first time. The system emits a single short beep and begins loading the…
- A user reports that a desktop powers on, emits a single short beep, and then displays a 'No boot device found' error. Which of the…
- A running PC with a dark screen is a video fault, not no power
If the machine POSTs, meaning fans spin, drive lights blink, and it beeps, but the screen stays dark, the fault is in the display path, not power. Check the monitor's power and input source, the video cable, onboard versus add-in-card output, and swap in a known-good monitor to isolate the layer.
Trap Confusing no display with no power; a lit, humming PC that shows nothing has a video or monitor problem, not a power-delivery one.
- Random shutdowns under load point at heat before the CPU
A system that runs hot and shuts down or throttles unexpectedly is usually thermal: dust-clogged fans and vents, a stopped fan, or dried-out thermal paste. Clean and cool it and check PSU load before you suspect the CPU or motherboard, because heat is the cheap and far more common cause.
Trap Replacing the CPU or board for heat-related shutdowns before cleaning the fans and vents and confirming the cooling works.
- Grinding or clicking means back up now, then check S.M.A.R.T.
A mechanical drive that grinds or clicks is failing right now, so capturing a backup comes before anything else. S.M.A.R.T. (Self-Monitoring, Analysis, and Reporting Technology) exposes the drive's own health counters and can flag a pending failure before it becomes fatal, but reads happen after the data is safe.
Trap Running a full scan or repair on a clicking drive before backing it up; the drive can fail completely mid-diagnostic.
- A single failed RAID member degrades the array, it does not lose it
In a redundant RAID (redundant array of independent disks) set, one failed drive usually drops the array to a degraded state that still serves data, so you replace the member and let the array rebuild. The real danger window is a second drive throwing S.M.A.R.T. warnings during that rebuild.
Trap Assuming any single-drive failure in a redundant RAID set means total data loss; a redundant array stays online in a degraded state.
- Swollen capacitors, a burning smell, or a bulging battery are stop-work signs
A few observations override the normal cheap-to-expensive order: bulging or leaking capacitors on the board, a burning smell or scorch marks, and a swollen lithium battery. Cut power, remove the unit from service, and replace the damaged part under ESD (electrostatic discharge) precautions rather than powering it back up to confirm the fault.
Trap Powering a board with swollen capacitors or a burning smell back on to reproduce the symptom; that risks fire and further damage.
3 questions test this
- A technician is diagnosing a desktop computer that intermittently fails to complete POST. Upon opening the case and visually inspecting the…
- A technician is troubleshooting a desktop that fails to boot. During physical inspection, the technician observes bulging capacitors near…
- A technician examines a laptop whose touchpad has become difficult to press and no longer clicks evenly, and the underside of the chassis…
- A 169.254.x.x address means DHCP failed, not that the NIC is dead
An APIPA (Automatic Private IP Addressing) address in 169.254.0.0/16 is self-assigned when a host requests DHCP and gets no reply. It is link-local, is never forwarded by a router, and hands the host no usable default gateway, so it is a DHCP-reachability diagnosis. Renew the lease, then check the cable, switch port, and DHCP server.
Trap Replacing the network card because of a 169.254 address; the adapter is working, it simply never reached a DHCP server.
- No link light means check the cable, port, and NIC first
No connectivity with a dark link LED and a failed ping to the default gateway is a physical-layer fault. Swap a known-good patch cable and try another switch port before you touch IP settings or drivers, because the problem is below the network layer.
- A duplicate-IP warning is two hosts sharing one static address
An IP conflict message means two devices are configured with the same static IP, which causes intermittent drops for both. Resolve it by moving one host to DHCP or assigning a unique static address outside the DHCP pool, since DHCP itself leases unique addresses.
Trap Blaming the DHCP server for an IP conflict; DHCP hands out unique leases, so a conflict comes from duplicate static addressing.
- Throughput far below the link rate points at duplex or cabling
Slow speeds, where measured throughput sits far under the negotiated link rate, most often come from a duplex mismatch (one side half-duplex, the other full) or marginal cabling. Check the negotiated speed and duplex settings and re-terminate a suspect cable run before assuming an upstream limit.
- Intermittent drops and high latency point at interference, cabling, or load
A link that works then stalls, with ping spikes and sporadic drops, points at interference (on Wi-Fi, an overlapping or crowded channel), a marginal cable, or congestion under load, rather than a hard failure. Reproduce it and isolate one variable at a time instead of swapping parts by guess.
- A link light that cycles up and down is a flapping port from a bad cable
Port flapping, where the link LED repeatedly comes up and drops, is almost always a marginal cable or connector or a duplex problem. Re-seat or replace the cable and check the switch port before you suspect the NIC or the switch hardware itself.
Trap Swapping the switch or the NIC for a flapping port before trying a new cable; a marginal cable or connector is the usual cause.
- For a 'what should they do NEXT' item, locate where the scenario stopped
A common troubleshooting stem gives a partial scenario and asks what to do next. The methodology itself is not tested, so the answer is not a step number; it is the action the situation calls for, and the loop makes it obvious: a confirmed theory leads to planning and implementing the fix, an implemented fix leads to verifying full functionality, and a verified fix leads to documenting the outcome.
Trap Choosing document the findings as the next step when the fix has been made but not yet verified; verification comes before documentation.
- Change one variable at a time so the cause stays provable
When implementing a fix, alter a single thing and retest before changing the next, so you know which change resolved the problem. Changing several things at once may clear the symptom but hides the cause and can introduce a new fault you cannot attribute.
Trap Applying several fixes together to save time; the problem may clear, but you cannot tell what fixed it or what you may have broken.
- A failing power supply shows as shutdowns under load and repeated power cycling
Unstable or insufficient power from a failing supply looks like sudden shutdowns only under heavy load, a brief power-on that immediately cycles off and retries, or fans and drives that pulse up and down as the rails waver. A power supply's own exhaust fan seizing, often heard as a grinding noise at the rear, overheats the unit into a protective shutdown, and because that fan is not separately serviceable the whole supply is replaced.
Trap Assuming overheating for load-related shutdowns when temperatures read normal and only the power delivery is unstable.
5 questions test this
- A user reports that their desktop runs fine while browsing the web but suddenly powers off without warning during graphics-intensive games.…
- When a user presses the power button, the case fans twitch for a moment and the LEDs flicker, then everything shuts off. The system repeats…
- A desktop has recently developed a loud grinding and rattling noise that the technician traces to the rear of the case, right where the AC…
- A desktop sometimes does not power on at all, and when it does run the case fans pulse up and down in speed while the hard drives audibly…
- A desktop runs normally right after a cold start but shuts itself down after several minutes of use. The technician observes that the power…
- Random crashes that name a different file or address each time point at failing RAM
Blue screens or stop errors that cite a different memory address or system file on each crash, corruption that is not tied to any one application, or freezes that appear only under heavy memory load are classic signs of failing RAM rather than a drive or CPU fault. Confirm it with an extended memory diagnostic such as Windows Memory Diagnostic or MemTest, and treat a module that is not fully recognized, or one whose removal ends the instability, as the bad stick to reseat or replace.
Trap Blaming the storage drive for varied stop errors when its self-test passes and a memory test fails.
6 questions test this
- A user asks a technician to add a second memory module to increase capacity. After the upgrade, the desktop boots but now freezes and…
- A workstation that has had no recent changes begins displaying varied stop errors and occasional application crashes. The technician runs a…
- A user reports that a desktop is stable during light use such as email and web browsing, but it freezes and crashes only when many…
- A user reports that a desktop frequently crashes with stop errors that reference a different system file each time. No hardware or software…
- A technician installs two identical 8 GB memory modules in a desktop, but the operating system reports only 8 GB of usable memory. The…
- A user experiences frequent, random blue screen crashes that reference a different memory address each time, along with occasional file…
- For a SOHO-wide internet outage, reboot the router and modem, then bypass to the modem to isolate router from ISP
When every wired and wireless client drops internet while the cabling and clients themselves test fine, power-cycle the all-in-one router and the broadband modem first, because a device left running for weeks can develop memory, session, or DHCP-table faults a restart clears. If the outage continues, connect one known-good computer straight into the modem: reaching the internet there puts the fault in the router, while a still-dead link points upstream to the ISP. Testing a wired client against the same router likewise separates a wireless-only fault from a whole-router one.
Trap Calling the ISP or swapping the router before a reboot and a direct-to-modem test have isolated the side at fault.
7 questions test this
- A technician at a SOHO is told that internet access drops out several times a day for every wired and wireless client, but cabling and the…
- A user connected to the SOHO wireless network reports no internet access. The technician wants to quickly determine whether the problem is…
- A SOHO reports that internet access for all wired and wireless clients has become intermittent throughout the morning, dropping and…
- Wireless users in a SOHO suddenly cannot reach the internet, and the office SSID no longer appears in their available networks list. Wired…
- A SOHO router has been powered on continuously for several weeks, and users now report that internet access for every client has become…
- Every device in a SOHO, both wired and wireless, suddenly loses internet access at the same time, and the clients are now displaying…
- Every wired and wireless client in a SOHO loses internet access several times an hour, but local file sharing between the computers keeps…
Troubleshooting Tools
Read full chapterUnlock with Premium — includes all practice exams and the complete study guide.