Study Guide · 220-1201

220-1201 Cheat Sheet

321 entries · 15 chapters · 5 domains

Mobile Devices

Mobile Device Hardware

Read full chapter

Cheat sheet

Sharp facts the exam loves — scan these before test day.

Sort every mobile part into serviceable module or sealed

The first move on any mobile repair is deciding whether a component is a serviceable module or a sealed part. Traditional laptops expose the battery, memory, storage, wireless card, keyboard, and display as replaceable modules, while phones, tablets, and thin ultrabooks increasingly glue or solder those same parts. Whether a part is a module or sealed often decides the job before you open the case.

Soldered LPDDR memory cannot be upgraded; only SO-DIMMs can

Laptop RAM in a SO-DIMM (small outline dual inline memory module) socket can be swapped or added, but many thin laptops use LPDDR (low-power DDR) chips soldered directly to the board, which are fixed for the life of the device. Before promising a memory upgrade, confirm the machine actually has SO-DIMM slots rather than soldered memory.

Trap Ordering a SO-DIMM upgrade for an ultrabook whose memory is soldered LPDDR; there is no socket to add it to.

Laptop storage is 2.5-inch SATA, M.2, or soldered eMMC

A serviceable laptop drive is a 2.5-inch SATA disk or an M.2 card, and an M.2 card can run either the SATA or the faster NVMe protocol, so check which the slot supports. Budget and ultrathin devices instead solder eMMC (embedded MultiMediaCard) storage to the board, which cannot be replaced or upgraded.

The lid is layered: the panel shows the image, the digitizer senses touch

A laptop or tablet lid is a stack of independent layers, so a fault usually lives in one layer, not the whole screen. The panel (LCD or OLED) produces the image, the digitizer senses touch, and the bezel holds the camera, microphone, and Wi-Fi antenna. An image that displays perfectly but ignores touch points squarely at the digitizer, not the panel.

Trap Replacing the whole display panel when only touch has failed; the panel is fine and the digitizer is the faulty layer.

A laminated screen replaces as one fused assembly

On most phones and many laptops the glass, digitizer, and panel are laminated into a single fused assembly, so you cannot separate cracked glass from a good panel. The repair replaces the whole unit, which is why a glass-only quote is usually wrong on a laminated device.

Trap Quoting a glass-only repair on a laminated screen, where the glass, digitizer, and panel come only as one bonded part.

LCD needs a backlight; OLED lights each pixel itself

An LCD filters a separate backlight through liquid crystals, so it always leaks some light and cannot reach a true black. An OLED emits light per pixel and switches pixels fully off, giving true blacks and a thinner panel with no backlight layer. This one difference drives most display comparisons.

TN panels are cheap and fast but shift color off-axis

A TN (twisted nematic) LCD has the fastest response and the lowest cost, but the narrowest viewing angles and weakest color, so brightness and color wash out as you move off-center. It suits budget or high-refresh use where viewing angle does not matter much.

Trap Specifying a TN panel for color-critical or shared-viewing work; its color and viewing angles shift too much for that.

Choose IPS for wide viewing angles and accurate color

An IPS (in-plane switching) LCD gives the widest viewing angles and the most accurate color of the LCD types, at higher cost and power draw than TN. It is the standard pick for design, photo, and any work where color fidelity or off-angle viewing matters.

VA panels trade response time for the highest LCD contrast

A VA (vertical alignment) LCD sits between TN and IPS: it offers the highest contrast ratio and deeper blacks than either, but a slower response that can smear fast motion. It fits media viewing where contrast matters more than speed.

OLED risks burn-in from static on-screen elements

Because each OLED pixel ages with use, a static element held on screen for long stretches, such as a taskbar or a channel logo, can ghost in permanently as burn-in. That makes OLED a poor fit for an always-on display showing fixed content, even though it gives the best blacks and contrast.

Trap Choosing OLED for a 24/7 kiosk or dashboard with a fixed interface; the static elements will burn in over time.

2 questions test this
Only legacy CCFL backlights use an inverter, not LED

A CCFL (cold cathode fluorescent lamp) backlight needs high-voltage AC, so laptops with one carry an inverter that converts the DC supply into that AC. Modern LED backlights run on low-voltage DC and have no inverter, so an inverter is a component only on older CCFL panels.

Trap Trying to replace the inverter on a modern LED-backlit laptop; LED backlights have none, so the dim-display fault is elsewhere.

Wi-Fi antennas route through the hinge into the lid

Laptop Wi-Fi antenna wires run from the wireless card on the motherboard, up through a hinge, and around the display bezel, because the raised, metal-free lid gives the best reception. Any screen replacement disturbs those leads, so re-seating them is part of the job.

Trap Blaming the wireless card or driver for weak Wi-Fi right after a screen repair, when an unseated antenna lead in the lid is the usual cause.

7 questions test this
WLAN cards do Wi-Fi and Bluetooth; WWAN cards do cellular

The internal wireless card is usually an M.2 or Mini-PCIe WLAN (wireless LAN) card that handles Wi-Fi and Bluetooth. Cellular data needs a separate WWAN (wireless WAN) card plus a SIM, which not every laptop includes. Both are field-replaceable modules on many laptops.

Mobile batteries are lithium-ion or lithium-polymer cells

Mobile devices use lithium-ion (Li-ion) cells, common as rigid rectangular laptop packs, or lithium-polymer (LiPo) cells, whose gel electrolyte can be formed thin and flexible, which is why phones and tablets favor them. Both store high energy in a small space, and both can swell when they fail.

A swollen battery is a hazard: replace it, never puncture it

A pack that has swelled has failed and is a fire and rupture risk, so take it out of service right away. Never puncture it, force-discharge it, or keep charging it to flatten it, and use a plastic tool rather than a metal pry to remove it. A phone whose screen or back panel is lifting is showing a swollen cell underneath.

Trap Puncturing a swollen pack or continuing to charge it to keep the device running; that risks fire and rupture.

1 question tests this
Disconnect the battery connector before other internal work

After powering down, unplug the battery connector first, before removing or reseating any other internal part, so no rail stays live and a slipped tool cannot short a powered board. This ordering is standard safe practice for laptop, phone, and tablet service.

1 question tests this
Modern batteries are glued in; older packs latch out

Older laptops hold the battery in an external bay that releases with a latch or slide, needing no tools. Most current laptops, and nearly all phones and tablets, bond the cell in with adhesive, so replacement means opening the case and freeing it carefully. Which mounting a device uses sets the whole procedure.

The built-in webcam and microphone sit in the display bezel

A laptop's built-in webcam and microphone are mounted in the top of the display bezel, alongside the antenna leads. Because they are integrated into the lid, a failed built-in camera often means servicing part of the display assembly rather than swapping a standalone module.

Camera and ribbon cables use ZIF connectors: lift the tab to release, seat fully, press to secure

Internal ribbon (flat flexible) cables such as a camera module's attach to the logic board through a ZIF (Zero Insertion Force) connector, a socket with a small hinged locking tab. To disconnect, lift the tab first and slide the cable out; to reconnect, lift the tab, slide the aligned cable fully in, and press the tab down to clamp it. A ribbon that is not fully seated, or whose tab is left open, makes no data connection, so a just-replaced camera shows a black screen or streaked images even though the part is good.

Trap Condemning a just-installed camera module as defective when a partially seated ribbon or an unlatched ZIF tab is the real fault.

9 questions test this

Mobile Accessories

Read full chapter
  • Pick a connection method by what must cross it and wired vs wireless
  • A USB-C port only does what the hardware behind it supports
  • micro-USB and mini-USB are legacy connectors that insert one way only
  • Bluetooth links accessories over about 10 meters after a one-time pairing
  • An accessory must be in discoverable mode before it can be paired
  • NFC only works within a few centimeters, so you tap instead of pairing
  • NFC handles contactless pay, transit cards, and tap-to-pair
  • A docking station adds capability; a port replicator only duplicates ports
  • Thunderbolt docks use the USB-C connector but add 40 Gbps and daisy-chaining
  • A USB-C dock carries data out, video to monitors, and power back in one cable
  • USB Power Delivery negotiates up to 100 W to charge laptops over USB-C
  • Active styluses pair over Bluetooth; passive styluses just conduct touch
  • Audio accessories connect by 3.5 mm jack, USB-C, or Bluetooth
  • Serial is a legacy, low-speed wired method largely replaced by USB
  • Bluetooth profiles decide what a link carries: A2DP for stereo, HFP for calls, HID for input

Unlock with Premium — includes all practice exams and the complete study guide.

Mobile Connectivity

Read full chapter
  • A phone prefers Wi-Fi and falls back to metered cellular data
  • A wrong APN breaks mobile data while voice still works
  • GSM identifies the subscriber by a swappable SIM; CDMA by the carrier database
  • An eSIM is an embedded SIM you reprogram in software
  • A PRL update refreshes the CDMA roaming table over the air
  • Cellular data climbs 3G, 4G LTE, then 5G
  • Only airplane mode cuts every radio at once
  • Wi-Fi trades range for speed across 2.4, 5, and 6 GHz
  • Sharing pushes the phone's own cellular link outward
  • Only a Wi-Fi hotspot serves several devices; tethering serves one
  • Shared devices spend the phone's cellular data cap
  • Bluetooth pairing runs enable, discoverable, select, confirm PIN, test
  • Paired Bluetooth devices reconnect automatically after the first time
  • Bluetooth is a short-range 2.4 GHz personal-area link
  • A VPN encrypts traffic over a link it does not create
  • A mobile VPN needs a server address, protocol, and authentication
  • Always-on VPN reconnects itself; per-app VPN routes only chosen apps
  • IMAP syncs mail across devices; POP3 downloads to one
  • Exchange syncs the calendar and contacts that IMAP alone will not
  • Account sync works because the server holds the master copy
  • Syncing large data over cellular counts against the data cap
  • Wi-Fi calling carries voice over Wi-Fi when the signal is weak

Unlock with Premium — includes all practice exams and the complete study guide.

Mobile Troubleshooting

Read full chapter
  • Try the cheapest fix before you open a mobile device
  • Diagnose a no-charge fault as cable, then port, then battery
  • A phone that won't charge often has a lint-packed port
  • A swollen battery is a fire hazard: remove it from service
  • Overheating first throttles, then shuts down to protect the device
  • Rapid battery drain is usually a background app, not a dead cell
  • Prove a black screen with an external display
  • A dim screen is a brightness setting until proven otherwise
  • A faint image under a flashlight means the backlight failed
  • Screen flicker that changes as you flex the lid is a cable
  • Image but no touch is a digitizer fault, not a panel fault
  • Ghost touches point at the digitizer, a cheap charger, or a protector
  • A screen that won't rotate is the auto-rotate setting, not the display
  • Cracked glass and dead touch are separate faults
  • Check airplane mode before troubleshooting any dead radio
  • Forget and rejoin a Wi-Fi network to clear a stale profile
  • Bluetooth pairing needs the accessory discoverable and in range
  • A cable that charges only at an angle is a worn port
  • Reseat the SIM when a phone loses cellular but has coverage
  • Weak signal right after a screen repair is an unseated antenna lead
  • Use ESD protection whenever you open a mobile device
  • Organize screws by location and never overtighten on reassembly
  • Screen lines, dead pixels, and stuck pixels that survive a restart are panel hardware faults
  • A phone that charges over USB but shows no storage is in charging-only mode or on a power-only cable

Unlock with Premium — includes all practice exams and the complete study guide.

Networking

Protocols and Ports

Read full chapter

Cheat sheet

Sharp facts the exam loves — scan these before test day.

Use connection-oriented TCP when every byte must arrive in order

TCP is connection-oriented: it opens a session, numbers every byte, acknowledges what arrives, and retransmits anything lost, so data lands complete and in order. That reliability costs setup round trips and header overhead, which is why it carries web, email, and file transfer where a corrupted result is unacceptable.

Trap Choosing UDP for a file transfer that must arrive intact; UDP never retransmits a lost datagram.

8 questions test this
UDP is connectionless: no handshake, no acknowledgment, no reordering

UDP sends each datagram on its own with almost no overhead and no setup delay, and it never confirms or reorders anything. That makes it the right transport for real-time voice and video, online games, and quick request-and-reply lookups, where a late packet is worse than a missing one.

Trap Assuming UDP guarantees ordered, reliable delivery; it has no sequence numbers and no acknowledgments.

15 questions test this
TCP opens a session with the three-way handshake

Before any TCP data flows, the client sends a SYN, the server replies SYN-ACK, and the client answers ACK, which establishes the connection. Only after that exchange does the sequenced, acknowledged data transfer begin.

8 questions test this
DNS runs on both UDP 53 and TCP 53

Ordinary name-to-IP lookups use UDP 53 for a fast single exchange, but DNS switches to TCP 53 for zone transfers and for responses too large to fit one UDP datagram. A single protocol using both transports is exactly the kind of detail the exam probes.

Trap Answering 'UDP only' for a DNS zone transfer; oversized transfers use TCP 53.

11 questions test this
SSH on TCP 22 is the encrypted replacement for Telnet on TCP 23

SSH gives an encrypted remote shell on port 22, while Telnet on port 23 sends everything, including the login, in cleartext. Any remote-administration question that mentions security wants SSH, not Telnet.

1 question tests this
RDP uses TCP 3389 for a graphical Windows remote desktop

RDP carries a full graphical Windows session over TCP 3389. Because it has a long brute-force and worm history, it should never be exposed raw to the internet; reach it through a VPN or a jump host.

Trap Exposing RDP 3389 directly to the internet instead of tunneling it through a VPN or jump host.

SMB uses TCP 445; the legacy NetBIOS path was 137-139

Modern Windows file and printer sharing uses direct-host SMB on TCP 445, while ports 137-139 are the older NetBIOS path. Like RDP, SMB 445 has a wormable history and should not face the internet.

Trap Citing port 139 for current SMB; direct-host SMB uses TCP 445, and 137-139 is the legacy NetBIOS range.

HTTP is TCP 80; HTTPS is TCP 443

Web traffic is cleartext HTTP on port 80 and TLS-encrypted HTTPS on port 443. The encrypted version is the same web protocol on a different port, so securing a site swaps 80 for 443.

FTP uses TCP 20 and 21: 21 controls the session, 20 carries data

FTP opens a control channel on port 21 and moves file data on port 20, and both channels are cleartext. Knowing which port is control versus data is a common exam detail.

2 questions test this
SMTP relays on TCP 25; authenticated clients submit on 587

Server-to-server mail relay uses SMTP on port 25, but an authenticated mail client submits outgoing mail on port 587, commonly upgraded with STARTTLS. Providers often block outbound 25 from clients to fight spam.

Trap Configuring a mail client to send on port 25; authenticated submission uses 587 and many ISPs block outbound 25.

2 questions test this
POP3 (110) downloads and deletes mail; IMAP (143) keeps it synced on the server

POP3 on port 110 pulls messages down and removes them from the server, while IMAP on port 143 keeps the mailbox synchronized so the same mail appears on every device. Choose IMAP when a user reads mail from more than one device.

Trap Choosing POP3 for a user who reads mail on several devices; POP3 removes messages from the server, IMAP keeps them synced.

DHCP uses UDP with the server on 67 and the client on 68

The DHCP client (port 68) broadcasts a DISCOVER because it has no address yet, and the server (port 67) answers, following the DORA sequence of Discover, Offer, Request, Acknowledge. Both ports are UDP.

Trap Swapping the DHCP ports; the server listens on UDP 67 (bootps) and the client on UDP 68 (bootpc).

3 questions test this
SNMP polls agents on UDP 161 and receives traps on UDP 162

An SNMP manager polls agents for status on port 161, and agents push unsolicited alerts, called traps, to the manager on port 162. Both run over UDP.

Trap Expecting an SNMP trap to arrive on 161; scheduled polls use 161, but agent traps arrive on 162.

4 questions test this
LDAP is TCP 389; the TLS version LDAPS is TCP 636

Directory queries, such as against Active Directory, run cleartext LDAP on port 389 and TLS-encrypted LDAPS on port 636. The secure variant moves to its own port like the other swaps.

5 questions test this
SFTP is an SSH subsystem on port 22, not FTP-over-TLS

SFTP is the file-transfer subsystem of SSH and runs on port 22, while FTPS is FTP wrapped in TLS. They secure file transfer by different mechanisms, so treating SFTP as FTP-over-TLS is wrong.

Trap Treating SFTP as FTP-over-TLS; SFTP runs inside SSH on port 22, and FTPS is the TLS-wrapped form of FTP.

1 question tests this
Secure mail retrieval ports: POP3S 995 and IMAPS 993

The TLS versions of the mailbox protocols each claim their own port: POP3S on 995 and IMAPS on 993. They pair with the cleartext POP3 110 and IMAP 143.

802.11 generations map to Wi-Fi 4, 5, and 6

The Wi-Fi Alliance renamed the recent 802.11 standards: 802.11n is Wi-Fi 4, 802.11ac is Wi-Fi 5, and 802.11ax is Wi-Fi 6. Wi-Fi 6E is the variant of Wi-Fi 6 extended into the 6 GHz band.

802.11ac (Wi-Fi 5) operates only in the 5 GHz band

Wi-Fi 5 (802.11ac) transmits only in the 5 GHz band, unlike 802.11n, which spans 2.4 and 5 GHz, and 802.11ax, which can use 2.4, 5, and 6 GHz. Dual-band Wi-Fi 5 gear still reaches a 2.4 GHz network, but through its 802.11n radio, since 802.11ac has no 2.4 GHz mode.

Trap Assuming 802.11ac itself runs on 2.4 GHz; the ac amendment is 5 GHz only, and a dual-band device falls back to 802.11n for 2.4 GHz.

1 question tests this
Only Wi-Fi 6E and later can use the 6 GHz band

The 6 GHz band is reachable only by Wi-Fi 6E (the 6 GHz extension of 802.11ax) and newer gear. A plain Wi-Fi 6 device without 6E stays on the 2.4 and 5 GHz bands.

Trap Assuming any Wi-Fi 6 device reaches 6 GHz; only the 6E variant and later use the 6 GHz band.

In 2.4 GHz only channels 1, 6, and 11 do not overlap

The 2.4 GHz channels overlap, so in North America access points should sit on channel 1, 6, or 11 at 20 MHz width. Any other choice causes adjacent-channel interference, and two APs on the same channel cause co-channel interference.

Trap Spacing access points on channels 1, 5, and 9; only 1, 6, and 11 are non-overlapping in 2.4 GHz.

10 questions test this
2.4 GHz reaches farthest; 5 and 6 GHz are faster at shorter range

The 2.4 GHz band penetrates walls best and reaches farthest but is the slowest and most congested. The 5 GHz band is much faster with more channels at shorter range, and 6 GHz is the widest and cleanest band but the shortest range.

4 questions test this
NFC works only at a touch, a few centimeters

NFC operates at 13.56 MHz over just a few centimeters, and that tiny range is itself the security model. It drives tap-to-pay, transit cards, and tap-to-pair, and it is a short-range relative of RFID.

Trap Choosing Bluetooth for a tap-to-pay terminal; contactless payment uses NFC at a few centimeters.

Bluetooth links peripherals across a room, about 10 meters

Bluetooth forms a personal-area network after a pairing step and carries keyboards, mice, headsets, speakers, and phone tethering, typically to about 10 meters for common class 2 radios. It is the room-scale wireless, one step up from NFC's touch range.

Passive RFID tags have no battery; active tags do

A passive RFID tag draws power from the reader's field and works only at very short range, while an active tag carries its own battery and reaches much farther. RFID drives inventory, asset tracking, and badge access.

Trap Assuming every RFID tag is battery-powered; passive tags are energized by the reader's radio field.

Long-range fixed wireless bridges point-to-point links across miles

Fixed wireless uses directional antennas aimed line-of-sight between two fixed points, on licensed or unlicensed spectrum, to connect buildings or rural sites where running cable is impractical. It is the technology for a distance far beyond what Wi-Fi covers.

NTP on UDP 123 keeps clocks in sync for time-sensitive services

NTP (Network Time Protocol) runs on UDP port 123 and synchronizes system clocks across networked devices. Services that depend on close time agreement, above all Kerberos authentication and correlated log timestamps, begin failing when server clocks drift apart, so a set of hosts showing different times points straight at NTP.

Trap Treating a Kerberos or logon failure as a broken authentication server when clock skew across the hosts is the real cause.

5 questions test this
TCP paces a sender with the sliding window the receiver advertises

TCP does flow control with a sliding window: the receiver advertises a window size that says how much unacknowledged data it can still buffer, and the sender never sends past it. This is what makes a fast sender slow down for a slow or congested receiver instead of overrunning its buffer, and it is separate from the connection setup and the acknowledge-and-retransmit that provide reliability.

Trap Crediting the three-way handshake, which only opens the session, with pacing the ongoing data flow.

6 questions test this
Wi-Fi 6 (802.11ax) is built for high-density environments

802.11ax, marketed as Wi-Fi 6, was designed to raise efficiency where many clients share the air, such as stadiums, convention centers, and crowded offices. It does this with OFDMA and enhanced MU-MIMO, which let one transmission serve several stations at once and lift the average throughput per client rather than only the peak speed.

Trap Choosing Wi-Fi 5 (802.11ac) for its raw peak speed when the real problem is many simultaneous clients.

4 questions test this

SOHO Networks

Read full chapter
  • Every IPv4 host needs an IP, subnet mask, default gateway, and DNS server
  • The subnet mask splits an address into network and host, and /24 equals 255.255.255.0
  • Without a default gateway a host reaches only its own subnet
  • Misconfigured DNS breaks names while numeric IPs still work
  • RFC 1918 reserves three private IPv4 ranges for internal use
  • NAT lets many private hosts share one public IP address
  • DHCP leases addresses to clients from a defined scope
  • A DHCP client gets its lease through the DORA exchange
  • A DHCP reservation pins an IP by MAC; a static address is set on the device
  • Put static addresses outside the DHCP scope to avoid conflicts
  • Point a port forward at a device with a reserved or static IP
  • Forward a single port rather than exposing a host in the DMZ
  • UPnP opens port forwards automatically, which is a security risk
  • Choose WPA3, fall back to WPA2 with AES, and never WEP or original WPA
  • WPA3-Personal uses SAE to block offline password cracking
  • On a WPA2 network choose AES, not the legacy TKIP cipher
  • Put visitors and IoT devices on an isolated guest network
  • Hiding the SSID is tidiness, not real security
  • MAC filtering is easily defeated by spoofing
  • Change the router's default administrator password first
  • IPv6 addresses are 128-bit, written in colon-separated hex
  • IPv6 needs no NAT and can self-configure with SLAAC
  • A client VPN tunnels a remote device onto the private network
  • A full tunnel routes all traffic; a split tunnel only the private-network traffic

Unlock with Premium — includes all practice exams and the complete study guide.

Networking Tools

Read full chapter
  • Crimp a plug on a patch cord; punch down a jack or panel
  • Use stranded cable for patch cords and solid cable for in-wall runs
  • Strip the jacket with a cable stripper before you terminate
  • T568A and T568B swap only the green and orange pairs
  • Match both ends to the same standard for a straight-through cable
  • Auto-MDIX makes crossover cables obsolete on gigabit ports
  • A cable tester reports the wiring fault type, not its distance
  • A split pair passes pin-to-pin continuity but breaks the pairing
  • A loopback plug tests whether a port can send and receive
  • Use a toner probe to trace one cable through a bundle
  • Read RSSI for signal strength and SNR for interference
  • Non-Wi-Fi sources raise the 2.4 GHz noise floor invisibly
  • A network tap copies live traffic inline without dropping frames
  • A wiremap cable tester uses a remote unit at the far end
  • Seat every conductor to the front of the plug before crimping, or pins read open
  • A Wi-Fi analyzer shows which channels nearby APs occupy so you can pick a clear one

Unlock with Premium — includes all practice exams and the complete study guide.

Hardware

RAM, CPUs, and Storage

Read full chapter

Cheat sheet

Sharp facts the exam loves — scan these before test day.

Each DDR generation fits only its own slot

DDR3, DDR4, and DDR5 modules are keyed with the notch in a different spot, so a stick physically will not seat in a slot built for another generation, and the memory controller supports only one generation. DDR4 and DDR5 DIMMs even share a 288-pin edge, yet the notch position still differs, so they are not interchangeable. Confirm the board's generation before ordering memory, because the fastest DDR5 kit is useless in a DDR4 board.

Trap Assuming DDR4 and DDR5 interchange because both are 288-pin DIMMs; the key notch sits in a different position and the controller accepts only one generation.

1 question tests this
DDR voltage drops as the generation climbs

Standard operating voltage falls each generation: DDR3 runs at 1.5 V (DDR3L at 1.35 V), DDR4 at 1.2 V, and DDR5 at 1.1 V, which is part of how newer memory raises bandwidth while holding power in check. The data rate moves the other way, from roughly 800 to 2133 MT/s (mega-transfers per second) on DDR3 up to 4800 MT/s and beyond on DDR5.

DIMM is for desktops, SO-DIMM is for laptops

A full-size DIMM (dual inline memory module) goes in desktop and server boards, while the shorter SO-DIMM (small outline DIMM) is the laptop and small-form-factor version of the same generation. The two are not cross-compatible in a slot, so a laptop upgrade needs SO-DIMM of the correct DDR generation. All-in-one PCs and mini PCs often use SO-DIMM to save space.

Trap Putting a desktop DIMM in a laptop; the laptop slot only accepts the shorter SO-DIMM even when the DDR generation matches.

1 question tests this
Dual channel needs matched modules in the paired slots

Installing one identical module in each memory channel lets the controller run dual channel, which roughly doubles memory bandwidth over a single stick; capable boards extend this to quad channel with four modules. The slots for each channel are color-coded or named in the manual, often the second slot of each channel, and the modules should match in size and speed. A single stick, or two mismatched sticks, drops the system back toward single-channel bandwidth.

Trap Putting both sticks in one channel's two slots; that leaves the array single-channel, so use one slot from each channel per the board's color coding.

1 question tests this
ECC memory corrects single-bit errors but needs platform support

ECC (error-correcting code) memory carries an extra chip that detects and fixes single-bit errors in real time, which is why servers and workstations that cannot tolerate silent corruption use it. It only works when the CPU and motherboard support ECC, so dropping an ECC module into a typical consumer desktop gives you no error correction. Mainstream desktops and laptops run non-ECC memory, trading that protection for lower cost.

Trap Assuming DDR5 on-die ECC turns every DDR5 module into ECC memory; on-die ECC only protects the chip's cells internally and does not report or correct errors to the system the way a true ECC DIMM does.

1 question tests this
Mixed memory runs at the slowest module's rating

When you mix modules of different speeds, the memory controller clocks the whole set to the slowest stick's supported rate, and mixing sizes or timings can force single-channel operation. For predictable dual-channel performance, install a matched kit that was sold and tested together. Faster memory in the mix does not raise the baseline; it just runs slower to stay compatible.

2 questions test this
LGA puts pins on the socket, PGA on the chip

An LGA (land grid array) socket holds the delicate pins while the CPU shows flat contact pads, so Intel mainstream sockets and AMD's newer AM5 are LGA. A PGA (pin grid array) chip carries the pins itself and drops into holes in the socket, as on older AMD sockets like AM4. The distinction decides where a bent pin lives and how carefully you handle each part during install.

Trap Treating the CPU as the damaged part when pins bend on an LGA system; there the pins are in the motherboard socket, not on the chip, so the board is what is bent.

8 questions test this
Thermal paste goes on thin, and too much insulates

Thermal paste fills the microscopic gaps between the CPU's heat spreader and the cooler base so heat can cross into the cooler; a thin, even layer is the goal. Too much paste acts as an insulator and can ooze onto the socket, while none at all leaves an air gap that causes overheating and thermal shutdowns. Reseating a cooler means cleaning off the old paste and applying fresh compound.

Trap Applying a thick blob of paste to be safe; excess compound insulates and can spill onto pins, so a thin even layer transfers heat better.

10 questions test this
A matching socket still needs chipset and BIOS support

A CPU has to fit the socket and be supported by the motherboard's chipset and firmware, because a newer chip can share a socket with older boards yet need a BIOS update before it will POST. Check the board maker's CPU support list, not just the socket name, before buying. A supported socket with stale firmware can leave the system dead until you flash the BIOS with a compatible chip.

Trap Assuming a socket match alone guarantees a CPU works; the same socket can need a BIOS update first, so an unsupported firmware version will not boot the chip.

Align the CPU by its corner marker and never force it

A CPU seats only one way, marked by a small triangle or notch that lines up with the matching mark on the socket, and it should settle in under its own weight with zero force. Forcing a misaligned chip bends pins, whether on the chip (PGA) or in the socket (LGA). Lower the retention arm to lock it once it sits flat.

1 question tests this
7200 RPM drives are faster; 5400 RPM run cooler and quieter

A hard disk drive's spindle speed sets its baseline performance, so a 7200 RPM drive reads and writes faster than a 5400 RPM drive of the same design. The 5400 RPM class runs cooler, quieter, and on less power, which is why laptops and bulk storage favor it, while 7200 RPM suits performance desktops. Spindle speed matters only for HDDs; an SSD has no platters to spin.

Trap Treating RPM as an SSD spec; solid-state drives have no spindle, so RPM is meaningless for them.

SSDs have no moving parts, so they beat HDDs on speed and shock

A solid-state drive stores data in flash memory with no platters or heads, giving far lower latency, faster boot and load times, silent operation, and much better shock resistance than a hard disk drive. An HDD still wins on cost per terabyte, which is why bulk and archival storage often stays on spinning disks. A common upgrade is to boot from an SSD and keep an HDD for large files.

SATA III caps a drive near 600 MB/s no matter the media

The SATA (Serial ATA) III bus runs at 6 Gb/s, which works out to roughly 550 to 600 MB/s of real throughput, and that ceiling applies whether the drive is a hard disk or a SATA SSD. A fast SATA SSD saturates the bus, so the only way past the limit is a different interface, which is exactly what NVMe over PCIe provides.

NVMe rides PCIe lanes to reach multi-gigabyte speeds

NVMe (Non-Volatile Memory Express) is a protocol that connects the SSD straight to the CPU over PCIe (PCI Express) lanes instead of the SATA bus, so a typical NVMe drive reaches 3,500 MB/s and up, several times a SATA SSD's ceiling. The trade is that NVMe needs an M.2 slot (or add-in card) wired for PCIe. For boot disks and heavy workloads, NVMe is the clear performance pick.

Trap Assuming any M.2 slot delivers NVMe speed; a slot wired only for SATA will not run an NVMe drive at all, so the slot has to provide PCIe lanes.

1 question tests this
An M.2 drive can be SATA or NVMe, so check the slot

M.2 is only a physical form factor, so an M.2 stick may speak either SATA or NVMe, and the two are not automatically interchangeable in a given slot. A slot's keying (B-key, M-key, or B+M) and the board manual tell you which interfaces it accepts. Match the drive's protocol to what the slot supports, or the drive runs at the wrong speed or not at all.

Trap Assuming every M.2 drive is NVMe; M.2 is just the shape, and a SATA M.2 drive behaves like a SATA drive despite the M.2 form factor.

1 question tests this
Know the physical form factors: 3.5in, 2.5in, and M.2

Desktop hard drives use the 3.5-inch form factor, while 2.5-inch bays hold laptop hard drives and SATA SSDs, and M.2 is the small gumstick card that mounts flat on the board (commonly the 2280 size, 22 mm by 80 mm). Form factor is about physical fit and mounting, separate from the SATA-versus-NVMe interface question. A 2.5-inch drive is always SATA; only M.2 or an add-in card carries NVMe.

1 question tests this
RAID 0 stripes for speed with zero redundancy

RAID 0 splits data across two or more drives (striping) to add their speed and capacity, but it stores no parity or mirror, so losing any single drive destroys the entire array. It fits scratch space and workloads that value throughput over safety. Because a single failure wipes everything, RAID 0 actually increases the chance of data loss versus one drive.

Trap Treating RAID 0 as safe because it spans multiple drives; it has no redundancy at all, and one failed drive loses the whole array.

4 questions test this
RAID 1 mirrors two drives for redundancy

RAID 1 writes the same data to two drives (mirroring), so the array keeps running if one drive fails and you rebuild by copying from the survivor. The cost is capacity: usable space equals one drive, or 50 percent of the raw total. It is the simplest way to protect a two-drive system against a single disk failure.

2 questions test this
RAID 5 stripes with distributed parity across three or more drives

RAID 5 stripes data with parity spread across at least three drives, so it survives one drive failure and rebuilds the lost data from parity, while usable capacity is the total minus one drive's worth. It balances redundancy and space more efficiently than mirroring, which is why it is common for file servers. A second drive failing before the rebuild finishes loses the array.

Trap Assuming RAID 5 survives two simultaneous drive failures; it tolerates only one, and a second failure during rebuild loses the array.

11 questions test this
RAID 10 mirrors then stripes for speed plus redundancy

RAID 10 stripes across mirrored pairs, needing at least four drives, so it delivers both the speed of striping and the fault tolerance of mirroring, tolerating a drive failure in each mirror. Usable capacity is 50 percent of the raw total, the same overhead as RAID 1. It is the go-to when a workload needs high performance and redundancy and can afford the drives.

3 questions test this
RAID protects against drive failure, not deletion or corruption

RAID keeps a system available when a disk fails, but it is not a backup, because deletions, corruption, ransomware, and controller faults propagate across the array immediately. You still need separate backups to recover from those events. Treating RAID as your only copy of the data is a classic mistake the exam probes.

Trap Relying on a redundant RAID array as the backup; RAID does not protect against deletion, corruption, or malware, which hit every drive at once.

1 question tests this
Tighten a CPU cooler gradually in a diagonal cross pattern

Secure a CPU cooler by turning its retention screws only a few turns each in a diagonal cross (X) pattern, cycling around until all are snug, so mounting pressure lands evenly across the CPU heat spreader for uniform thermal-paste contact. Fully tightening one corner first tilts the cooler and leaves poor contact. A cooler that is loose or unevenly mounted loses that contact and can overheat and shut the system down within minutes of boot.

Trap Fully tightening one corner screw before the others, which tilts the cooler off the die.

5 questions test this
Set the UEFI SATA mode to RAID for an array, AHCI for a single drive

The motherboard's onboard RAID utility only appears if you first set the SATA controller mode to RAID in UEFI/BIOS; left on AHCI or IDE, the RAID option ROM never loads and no array can be built during POST. For a normal single SATA drive or SSD, AHCI is the correct mode, enabling native command queuing and hot-plug for the best performance. The mode is a firmware setting, not something the drive or the operating system selects on its own.

Trap Leaving the SATA mode on AHCI or IDE and expecting the RAID utility to appear at POST.

4 questions test this

Cables and Connectors

Read full chapter
  • Identify a cable by its connector, then confirm speed and length
  • A connector shape does not promise a capability
  • HDMI is the video connector that also carries audio
  • Choose DisplayPort for high refresh rates and multi-monitor
  • VGA is the analog blue 15-pin connector, video only
  • Read a DVI plug by its variant: DVI-A, DVI-D, or DVI-I
  • A passive adapter only re-routes; digital-to-analog needs an active adapter
  • USB-A inserts one way; USB-C and Lightning are reversible
  • One USB-C cable can carry data, power, and video together
  • USB speed rides the version, not the connector shape
  • Thunderbolt 3 and 4 run 40 Gbps over the USB-C connector
  • Lightning is Apple's proprietary connector, not interchangeable with USB-C
  • A SATA drive needs two connectors: 7-pin data and 15-pin power
  • SATA revision sets the speed; the connector stays the same
  • eSATA is external SATA that carries data only, not power
  • RJ45 (8P8C) terminates Ethernet; RJ11 is the smaller phone connector
  • Cat 6 carries 10 Gbps only to 55 m; Cat 6a reaches the full 100 m
  • Cable in an air-handling space must be plenum-rated
  • Coax RG-6 with an F-type connector is the cable-internet drop
  • Single-mode fiber goes farther by laser; multimode is shorter by LED
  • Fiber ends in LC, SC, or ST connectors
  • Choose fiber for distance or heavy interference
  • Identify the drive and AC power connectors: SATA power, Molex, and the AC cord
  • HDMI comes in three sizes: Standard, Mini, and Micro

Unlock with Premium — includes all practice exams and the complete study guide.

Peripheral Devices

Read full chapter
  • Every peripheral installs in the same order: connect, driver, configure
  • Memorize the laser imaging steps in order: processing, charging, exposing, developing, transferring, fusing, cleaning
  • Fusing, not transferring, is the heat step that makes toner permanent
  • Charging conditions the drum with a uniform charge before the laser writes
  • Laser prints with dry toner powder, not liquid ink
  • A laser maintenance kit replaces the fuser and rollers on a page-count schedule
  • Inkjet sprays liquid ink and its printhead can clog when idle
  • Calibrate an inkjet with head alignment so lines and colors register
  • Thermal printers use heat on special paper and need no ink
  • Impact (dot-matrix) is the only printer that makes carbon copies
  • An impact printer's consumables are the inked ribbon and tractor-feed paper
  • 3D printing is additive: FDM melts filament, resin (SLA) cures resin with light
  • PCL is HP's fast everyday PDL; PostScript is Adobe's for precise graphics
  • A printer spitting pages of code is a PDL or driver mismatch, not hardware
  • The print spooler queues jobs; restart it when the queue is stuck
  • Connect a printer three ways: local USB, wired network, or wireless
  • A print server shares one printer's queue among many users
  • Use a flatbed for bound or delicate originals, an ADF for loose stacks
  • A KVM switch runs several PCs from one keyboard, monitor, and mouse
  • Run the color-calibration utility when laser colors shift or fringe
  • Laser feed jams trace to worn pickup rollers or a worn separation pad
  • Printer firmware updates fix bugs and patch security, from the maker's site

Unlock with Premium — includes all practice exams and the complete study guide.

Motherboards and Power

Read full chapter
  • Pick the form factor from case size and how many slots you need
  • A PCIe slot's length is its lane count, and lanes are bandwidth
  • Each PCIe generation doubles per-lane bandwidth, and mixing runs slower
  • The chipset, not just the socket, decides which CPU a board supports
  • A 4-pin fan header does PWM speed control; a 3-pin header does not
  • Front-panel LEDs are polarized; the power and reset switches are not
  • The board needs both the 24-pin ATX and the separate 4+4-pin EPS
  • UEFI replaces BIOS and is what boots a drive larger than 2 TB
  • Secure Boot blocks unsigned bootloaders and needs UEFI
  • Enable CPU virtualization in UEFI before running VMs
  • Boot order picks which device the firmware tries first
  • A dead CR2032 CMOS battery loses the clock and BIOS settings at power-off
  • Clear CMOS to wipe a bad setting or a forgotten BIOS password
  • The TPM stores encryption keys and is required for Windows 11
  • Size the PSU for the +12 V load with headroom, led by the GPU
  • A higher 80 PLUS tier wastes less power, it does not add performance
  • Modular only means detachable cables, not more wattage
  • Each PSU connector feeds a specific part, and GPUs use 6+2-pin PCIe
  • Set the 115/230 V switch to the local mains, or the PC fails or fries
  • Balance intake and exhaust for a front-to-back airflow path
  • A heat sink needs thermal-paste contact to move heat off the chip
  • Use a liquid AIO for a hot CPU; it is sealed and needs no refilling
  • Fewer cores or a low clock than the CPU's spec is usually a UEFI setting
  • The UEFI hardware monitor shows temps and fan RPM and holds the fan curve

Unlock with Premium — includes all practice exams and the complete study guide.

Virtualization and Cloud Computing

Virtualization Concepts

Read full chapter

Cheat sheet

Sharp facts the exam loves — scan these before test day.

A virtual machine is a full computer defined in software

A virtual machine (VM) has its own virtual CPU, memory, disk, and network adapter and runs its own guest operating system, which behaves as if it owned real hardware. The physical machine it runs on is the host, and one host can run many VMs at the same time. Because the VM is software, you can copy, snapshot, move, or delete a whole computer as a set of files.

2 questions test this
The hypervisor both shares the host and isolates the guests

A hypervisor, also called the virtual machine monitor, creates VMs, divides one host's CPU, RAM, storage, and network among them, and keeps each VM isolated so a fault or infection in one cannot reach the host or its neighbors. NIST frames it as the component that manages the guest operating systems and controls the flow of instructions between the guests and the physical hardware. Sharing and isolating are its two jobs, and most exam scenarios reward matching a requirement to one of them.

Type 1 hypervisors run on bare metal for servers

A Type 1 (bare-metal) hypervisor installs directly on the hardware with no host operating system beneath it, so it effectively is the host's OS. With no extra layer to cross it has lower overhead and a smaller attack surface, which is why data centers and servers use it. VMware ESXi and Microsoft Hyper-V are the standard examples.

Trap Assuming a Type 1 hypervisor needs Windows or Linux installed underneath it first; it replaces that general-purpose OS rather than running on top of one.

12 questions test this
Type 2 hypervisors run as an app on a desktop OS

A Type 2 (hosted) hypervisor runs as an ordinary application on top of an operating system you already booted, such as Windows or macOS. That makes it the easy way to run a second OS on a laptop or workstation, at the cost of an extra host-OS layer between the VMs and the hardware. VMware Workstation, Oracle VirtualBox, and Parallels Desktop are Type 2.

Trap Assuming every VMware product is the same type; VMware Workstation is Type 2 (hosted) while VMware ESXi is Type 1 (bare-metal).

12 questions test this
Hyper-V is a Type 1 hypervisor even on a desktop

Microsoft Hyper-V is a bare-metal (Type 1) hypervisor, and enabling it on Windows 11 does not make it Type 2. When the Hyper-V feature turns on, Windows itself is shifted to run on top of the hypervisor, so the hypervisor still sits directly on the hardware. Do not classify a hypervisor by whether you started it from a desktop.

Trap Calling client Hyper-V Type 2 because you enabled it from within Windows; the hypervisor runs beneath Windows, which makes it Type 1.

Client Hyper-V needs a 64-bit SLAT CPU and at least 4 GB RAM

Microsoft's client Hyper-V requires a 64-bit processor with SLAT (second-level address translation), VM Monitor Mode extensions, hardware-enforced DEP (the Intel XD bit or the AMD NX bit), and at least 4 GB of RAM, plus virtualization enabled in firmware. SLAT lets the hardware translate a guest's memory addresses instead of the hypervisor, which cuts overhead. Running systeminfo on Windows reports whether each requirement is met.

Size the host for itself plus every VM running at once

Each running VM reserves a real slice of the host's CPU, memory, disk, and network, so a host must cover its own needs plus the sum of what its VMs consume at the same time. Memory is usually the first ceiling: four VMs assigned 4 GB each want roughly 16 GB before the host's own overhead. Undersize any resource and VMs either fail to start or crawl as they contend for it.

Trap Planning a host around a single VM's requirements; the host must carry all concurrent VMs plus its own overhead.

Oversubscribing resources works only until VMs peak together

A hypervisor can oversubscribe, allocating VMs more virtual CPU or memory than the host physically has, on the bet that not all of them peak at once. It breaks when they do, so leave headroom for the host and keep total VM demand under the host's real capacity. This is a scheduling gamble, not free capacity.

Trap Assigning nearly all of the host's RAM to VMs; starving the host's own operating system slows every guest at once.

1 question tests this
Use a VM to run legacy or cross-platform software

When an application needs an operating system your hardware does not run, put it in a VM with the OS it requires, such as an old Windows release for a legacy app or Linux on a Windows host. This avoids buying and maintaining separate physical hardware for each platform. The VM's isolation also keeps an unsupported legacy OS off the rest of the machine.

2 questions test this
Snapshots make VMs ideal for test and development

A snapshot captures a VM's exact state so you can make risky changes and then roll straight back if they go wrong. That lets a test and development workflow build, break, and rebuild an environment that mirrors production without touching real systems. Reverting the snapshot or discarding the VM returns to a known-good state in seconds.

2 questions test this
A sandbox is a disposable, isolated place to run risky things

A sandbox is a throwaway isolated environment for safely running one untrusted app or file. Windows Sandbox is the built-in example: it isolates whatever you install from the host using hypervisor-based virtualization, and closing it deletes all software, files, and state, so every launch is a fresh, clean instance. It needs Windows Pro, Enterprise, or Education (not Home) and virtualization enabled in firmware.

Trap Reaching for a full persistent VM just to open one suspicious file; a sandbox discards everything on close with no cleanup, which a standing VM does not.

3 questions test this
Clone one VM image to give every trainee an identical lab

Because a VM is a set of files, you can clone one prepared image so every learner or tester gets the same environment and can reset it to a clean state on demand. That makes training rooms and QA labs consistent and cheap to rebuild. The same isolation means one student's mistake stays inside that student's VM.

1 question tests this
Consolidate many VMs on one host to save hardware and power

Resource efficiency is the core reason data centers virtualize: packing many VMs onto one capable host raises utilization and cuts hardware count, power draw, cooling, and rack space. A Type 1 hypervisor does this with the least overhead. The trade is that the shared host becomes a single point that must be sized and protected for all of its VMs.

VM isolation contains a crash or malware to one guest

The isolation a hypervisor enforces is the security payoff: a bug, a bad patch, or malware in one VM stays inside that VM instead of spreading to the host or its neighbors. This is why untrusted or experimental work belongs in a VM. Isolation is a property of the virtualization boundary, not something the guest OS provides for itself.

1 question tests this
VM escape is the worst-case break of guest isolation

A VM escape is code inside a guest breaking out of its VM to reach the hypervisor or the other guests, which defeats the isolation the whole model depends on. It is the most serious virtualization flaw because it crosses the boundary that is supposed to contain each guest. Keeping the hypervisor patched and limiting what a VM can touch are the routine defenses.

Trap Confusing VM escape with resource exhaustion or VM sprawl; escape specifically means breaking out of a guest to reach the hypervisor or other guests.

VMs on the same virtual switch are not automatically walled off

VMs reach the network through a virtual switch the hypervisor presents, mapped onto the host's physical adapter. Isolation of compute does not imply isolation of network: a VM sharing a virtual switch with production can talk to it unless you segment them. Put a VM on a separate switch or segment the network when it must stay off other traffic.

Trap Assuming a VM is network-isolated just because it is a separate machine; sharing a virtual switch with production leaves it reachable until you segment it.

Cloud Computing Models

Read full chapter
  • A true cloud has all five NIST essential characteristics
  • On-demand self-service means provisioning with no human help
  • Broad network access serves any standard client over the network
  • Resource pooling is multi-tenancy: one shared pool serves many customers
  • Elasticity scales out and back in automatically; scalability only adds
  • Measured service meters usage so cloud can bill pay-as-you-go
  • IaaS rents raw infrastructure and leaves the OS to you
  • PaaS runs the OS and runtime; you deploy only your app
  • SaaS delivers a finished app; you manage only settings and data
  • IaaS to PaaS to SaaS, the provider owns more of the stack
  • DaaS delivers a whole desktop the way SaaS delivers an app
  • On-premises VDI runs on your servers; DaaS runs on the provider's
  • Public cloud is open to the general public on shared infrastructure
  • Private cloud means dedicated to one org, not necessarily on-premises
  • Community cloud is shared by organizations with a common concern
  • Hybrid cloud binds two or more distinct clouds so workloads move
  • Deployment model and service model are independent choices
  • High availability is about staying up, not about handling load
  • File synchronization keeps files identical across a user's devices
  • Shared resources are internal in a private pool, external in a public one
  • Non-persistent VDI hands out a fresh pooled desktop each login and discards changes at logout
  • A thin client is a minimal endpoint that offloads its computing to a central server
  • A lost thin client exposes no data because VDI keeps everything on the server

Unlock with Premium — includes all practice exams and the complete study guide.

Hardware and Network Troubleshooting

Diagnosing Issues

Read full chapter

Cheat sheet

Sharp facts the exam loves — scan these before test day.

Run the six troubleshooting steps in their fixed order

CompTIA's methodology is a fixed sequence: identify the problem, establish a theory of probable cause, test the theory to determine the cause, establish a plan of action and implement the solution, verify full system functionality and add preventive measures, then document the findings, actions, and outcomes. CompTIA publishes this methodology with the 220-1201 objectives as a competency standard and states that the methodology itself will not be tested, so learn the order as working practice; what is graded is reading a symptom back to its cause and naming the right next action.

Trap Jumping to a plan of action or a parts swap before the theory has actually been tested; testing the theory is its own step and comes first.

In step one, gather information and back up before you change anything

Identifying the problem means interviewing the user, asking what changed, reproducing the symptom, and inquiring about recent environmental or infrastructure changes such as an office move or a power event. If a planned fix could put data at risk, back it up first, because a lost drive you could have imaged is a self-inflicted second problem.

Trap Reaching for a reimage, repartition, or drive swap before backing up data the repair could destroy.

Question the obvious before you theorize an expensive failure

Step two starts with the cheap, likely causes and works up: a loose or unplugged cable, a wall switch, a disabled adapter, or the wrong monitor input before a dead motherboard or PSU. When the symptom is unfamiliar, external or internal research (vendor documentation, a beep-code table, a knowledge base) is a legitimate part of forming the theory, not an admission of defeat.

An unconfirmed theory means form a new one or escalate, never repair

Testing the theory has two outcomes: confirmed sends you to a plan of action, and not confirmed sends you back to establish a new theory or to escalate to someone with more access or expertise. You never move from an unconfirmed theory straight to ordering or swapping a part.

Trap Continuing to swap parts by trial and error when a theory keeps failing, instead of escalating to someone with more access or expertise.

A repair is not done until you verify full functionality and document

Step five verifies the original complaint is gone and nothing new broke, and where applicable adds preventive measures such as clearing dust, securing a loose cable, or scheduling a firmware update. Step six documents the findings, actions, and outcomes so the next technician starts ahead. Stopping after the part swap leaves the job formally incomplete.

For a PC with no power at all, work the power path from the outside in

No fans and no lights is a power problem, not a POST problem, so trace the power path in order: wall outlet, surge strip, the PSU voltage switch and power switch, the 24-pin and CPU power connectors, and the front-panel power button header. Test those cheap causes before you condemn the power supply or the board.

Trap Assuming a dead motherboard when a flipped PSU switch, a dead outlet, or a loose power connector is the cheaper and likelier cause.

No POST means re-seat RAM and GPU, clear CMOS, and read the codes

When a system powers on but never begins to boot, it is failing POST (power-on self-test, the firmware's start-up hardware check). Re-seat RAM and the GPU, clear CMOS, boot with minimal hardware, and match the beep or POST code to the motherboard or BIOS vendor's table to localize the failing component.

Trap Treating a no-POST machine as a no-power fault and replacing the PSU, when the system already powers on and the fault is downstream.

18 questions test this
A single boot beep is normal; a repeating pattern is a coded error

One short beep at boot is usually the normal, successful POST all-clear on most systems, while a repeating or patterned beep is a coded hardware error. The pattern's meaning is specific to the motherboard or BIOS/UEFI vendor, so look it up rather than guessing which component it names.

Trap Reading a single short boot beep as a fault; on most systems it is the normal signal that POST passed.

6 questions test this
A running PC with a dark screen is a video fault, not no power

If the machine POSTs, meaning fans spin, drive lights blink, and it beeps, but the screen stays dark, the fault is in the display path, not power. Check the monitor's power and input source, the video cable, onboard versus add-in-card output, and swap in a known-good monitor to isolate the layer.

Trap Confusing no display with no power; a lit, humming PC that shows nothing has a video or monitor problem, not a power-delivery one.

Random shutdowns under load point at heat before the CPU

A system that runs hot and shuts down or throttles unexpectedly is usually thermal: dust-clogged fans and vents, a stopped fan, or dried-out thermal paste. Clean and cool it and check PSU load before you suspect the CPU or motherboard, because heat is the cheap and far more common cause.

Trap Replacing the CPU or board for heat-related shutdowns before cleaning the fans and vents and confirming the cooling works.

1 question tests this
Grinding or clicking means back up now, then check S.M.A.R.T.

A mechanical drive that grinds or clicks is failing right now, so capturing a backup comes before anything else. S.M.A.R.T. (Self-Monitoring, Analysis, and Reporting Technology) exposes the drive's own health counters and can flag a pending failure before it becomes fatal, but reads happen after the data is safe.

Trap Running a full scan or repair on a clicking drive before backing it up; the drive can fail completely mid-diagnostic.

A single failed RAID member degrades the array, it does not lose it

In a redundant RAID (redundant array of independent disks) set, one failed drive usually drops the array to a degraded state that still serves data, so you replace the member and let the array rebuild. The real danger window is a second drive throwing S.M.A.R.T. warnings during that rebuild.

Trap Assuming any single-drive failure in a redundant RAID set means total data loss; a redundant array stays online in a degraded state.

Swollen capacitors, a burning smell, or a bulging battery are stop-work signs

A few observations override the normal cheap-to-expensive order: bulging or leaking capacitors on the board, a burning smell or scorch marks, and a swollen lithium battery. Cut power, remove the unit from service, and replace the damaged part under ESD (electrostatic discharge) precautions rather than powering it back up to confirm the fault.

Trap Powering a board with swollen capacitors or a burning smell back on to reproduce the symptom; that risks fire and further damage.

3 questions test this
A 169.254.x.x address means DHCP failed, not that the NIC is dead

An APIPA (Automatic Private IP Addressing) address in 169.254.0.0/16 is self-assigned when a host requests DHCP and gets no reply. It is link-local, is never forwarded by a router, and hands the host no usable default gateway, so it is a DHCP-reachability diagnosis. Renew the lease, then check the cable, switch port, and DHCP server.

Trap Replacing the network card because of a 169.254 address; the adapter is working, it simply never reached a DHCP server.

1 question tests this
No link light means check the cable, port, and NIC first

No connectivity with a dark link LED and a failed ping to the default gateway is a physical-layer fault. Swap a known-good patch cable and try another switch port before you touch IP settings or drivers, because the problem is below the network layer.

1 question tests this
A duplicate-IP warning is two hosts sharing one static address

An IP conflict message means two devices are configured with the same static IP, which causes intermittent drops for both. Resolve it by moving one host to DHCP or assigning a unique static address outside the DHCP pool, since DHCP itself leases unique addresses.

Trap Blaming the DHCP server for an IP conflict; DHCP hands out unique leases, so a conflict comes from duplicate static addressing.

Throughput far below the link rate points at duplex or cabling

Slow speeds, where measured throughput sits far under the negotiated link rate, most often come from a duplex mismatch (one side half-duplex, the other full) or marginal cabling. Check the negotiated speed and duplex settings and re-terminate a suspect cable run before assuming an upstream limit.

Intermittent drops and high latency point at interference, cabling, or load

A link that works then stalls, with ping spikes and sporadic drops, points at interference (on Wi-Fi, an overlapping or crowded channel), a marginal cable, or congestion under load, rather than a hard failure. Reproduce it and isolate one variable at a time instead of swapping parts by guess.

1 question tests this
A link light that cycles up and down is a flapping port from a bad cable

Port flapping, where the link LED repeatedly comes up and drops, is almost always a marginal cable or connector or a duplex problem. Re-seat or replace the cable and check the switch port before you suspect the NIC or the switch hardware itself.

Trap Swapping the switch or the NIC for a flapping port before trying a new cable; a marginal cable or connector is the usual cause.

For a 'what should they do NEXT' item, locate where the scenario stopped

A common troubleshooting stem gives a partial scenario and asks what to do next. The methodology itself is not tested, so the answer is not a step number; it is the action the situation calls for, and the loop makes it obvious: a confirmed theory leads to planning and implementing the fix, an implemented fix leads to verifying full functionality, and a verified fix leads to documenting the outcome.

Trap Choosing document the findings as the next step when the fix has been made but not yet verified; verification comes before documentation.

Change one variable at a time so the cause stays provable

When implementing a fix, alter a single thing and retest before changing the next, so you know which change resolved the problem. Changing several things at once may clear the symptom but hides the cause and can introduce a new fault you cannot attribute.

Trap Applying several fixes together to save time; the problem may clear, but you cannot tell what fixed it or what you may have broken.

1 question tests this
A failing power supply shows as shutdowns under load and repeated power cycling

Unstable or insufficient power from a failing supply looks like sudden shutdowns only under heavy load, a brief power-on that immediately cycles off and retries, or fans and drives that pulse up and down as the rails waver. A power supply's own exhaust fan seizing, often heard as a grinding noise at the rear, overheats the unit into a protective shutdown, and because that fan is not separately serviceable the whole supply is replaced.

Trap Assuming overheating for load-related shutdowns when temperatures read normal and only the power delivery is unstable.

5 questions test this
Random crashes that name a different file or address each time point at failing RAM

Blue screens or stop errors that cite a different memory address or system file on each crash, corruption that is not tied to any one application, or freezes that appear only under heavy memory load are classic signs of failing RAM rather than a drive or CPU fault. Confirm it with an extended memory diagnostic such as Windows Memory Diagnostic or MemTest, and treat a module that is not fully recognized, or one whose removal ends the instability, as the bad stick to reseat or replace.

Trap Blaming the storage drive for varied stop errors when its self-test passes and a memory test fails.

6 questions test this
For a SOHO-wide internet outage, reboot the router and modem, then bypass to the modem to isolate router from ISP

When every wired and wireless client drops internet while the cabling and clients themselves test fine, power-cycle the all-in-one router and the broadband modem first, because a device left running for weeks can develop memory, session, or DHCP-table faults a restart clears. If the outage continues, connect one known-good computer straight into the modem: reaching the internet there puts the fault in the router, while a still-dead link points upstream to the ISP. Testing a wired client against the same router likewise separates a wireless-only fault from a whole-router one.

Trap Calling the ISP or swapping the router before a reboot and a direct-to-modem test have isolated the side at fault.

7 questions test this

Troubleshooting Tools

Read full chapter
  • Measure voltage with the power on, continuity and resistance with it off
  • A multimeter reads voltage, resistance, continuity, and current
  • ATX rails are +3.3, +5, and +12 V, good within about 5 percent
  • Use continuity mode to tell a good fuse from a blown one
  • The power-supply tester gives a quick go/no-go; the multimeter gives the exact value
  • A PSU that passes an unloaded tester can still fail under real load
  • No Power-Good signal means the board never leaves reset
  • A POST card shows the code where boot halts when there is no video
  • POST progress codes are written to I/O port 80h
  • Onboard CPU, DRAM, VGA, and BOOT LEDs replace a POST card
  • Distance to a cable fault needs a TDR, not a basic cable tester
  • When a run has no link, test the cable first, then the port
  • An ESD spark too small to feel can still kill a chip
  • Never wear an ESD strap near a CRT or an open power supply
  • Power down and unplug before you work inside a machine
  • Keep a work area near 40 to 60 percent humidity to limit ESD
  • Read a wall outlet on AC volts, but a battery, adapter, or PSU rail on DC volts

Unlock with Premium — includes all practice exams and the complete study guide.