CompTIA A+ Core 2 (220-1202) flashcards
171 free flashcards. Tap a card to flip it.
Ransomware Containment
Flip cardThe first response to detected ransomware is to isolate the infected system from the network to prevent further spread before remediation.
- Disconnect network cable or disable Wi-Fi immediately
- Never pay the ransom as a first response
- Identify, remediate, then restore from clean backups
Memory trick: Cut the cord before the fire spreads to the rest of the network
ReFS (Resilient File System)
Flip cardA Microsoft proprietary file system designed to maximize data availability, scale efficiently to large data sets, and provide data integrity with features like self-healing and checksumming.
- Designed for high data availability and resilience against corruption.
- Includes integrity streams (checksums) for metadata and optionally user data.
- Supports 'integrity scanners' for proactive corruption detection and repair.
- Optimized for large data sets and high-performance storage scenarios.
Memory trick: ReFS: 'RE'siliency 'FS' for 'Fantastic' 'Safety'!
Fileless Malware Detection
Flip cardFileless malware resides in memory or abuses legitimate tools (e.g., PowerShell, WMI) rather than writing files to disk, evading traditional antivirus signature scans.
- Traditional file-based AV scans often miss fileless malware
- Windows Event Viewer PowerShell/Security logs can reveal suspicious execution
- Detection often requires behavioral/log analysis rather than file scanning
Memory trick: No files to scan? Check the logs — 'Ghosts leave footprints in Event Viewer'
Scripting Loop
Flip cardA programming construct that repeats a block of code for each item in a set, such as processing every file in a folder.
- Common types: For, ForEach, While
- Essential for batch processing multiple items
- Different from variables, comments, or environment variables
Memory trick: Loop it to do it again and again.
High Disk Utilization Troubleshooting
Flip cardHigh disk utilization, often seen as 100% in Task Manager, indicates that the storage device is constantly active, leading to severe system slowdowns and unresponsiveness.
- Common causes include runaway background processes, malware, or failing hardware.
- Troubleshooting involves identifying the process consuming disk resources.
- SSDs should not be defragmented; this is for HDDs.
Memory trick: Identify the hungry process eating your disk.
Malicious Browser Extension
Flip cardA browser add-on or plugin that appears legitimate but is designed to perform harmful actions, such as changing browser settings, injecting advertisements, tracking user data, or redirecting traffic, often without the user's full knowledge or consent.
- Installed by the user (often unknowingly)
- Can alter browser settings (homepage, search engine)
- Injects ads or redirects traffic
- May track browsing history and personal data
Memory trick: An extension can hijack your browser, but XSS is a script, not an install.
UPS vs Surge Protector
Flip cardA UPS provides both surge suppression and temporary battery backup power, while a surge protector only guards against voltage spikes.
- UPS allows safe shutdown time during outages
- Surge protectors do not supply power during an outage
- UPS units are rated in VA/watts for runtime capacity
Memory trick: UPS keeps you Up even when Power Stops.
DISM (Deployment Image Servicing and Management)
Flip cardA command-line tool used to service a Windows image or prepare a Windows Preinstallation Environment (Windows PE) image. It can be used to repair a corrupted Windows installation.
- Can repair the Windows component store.
- Uses Windows Update or a specified source for repair files.
- Often used after 'sfc' fails to resolve issues.
Memory trick: DISM is for 'DISM-antling' and 'Reassembling' your Windows image.
Rogue Antivirus (Scareware)
Flip cardMalware or a malicious webpage that displays fake security warnings to frighten users into paying for bogus software or calling a scam support line.
- Displays exaggerated 'infection' counts
- Pressures immediate action (call now, pay now)
- Never legitimate — close via Task Manager, don't call the number
Memory trick: Scareware screams scary numbers to steal your money
Open-Source License
Flip cardA software license that grants users the right to view, modify, and redistribute the source code, often under conditions such as attribution or share-alike requirements.
- Contrasts with proprietary/closed-source licenses
- Common examples: GPL, MIT, Apache License
- Redistribution rights vary by specific license terms
Memory trick: Open source = open code, open to change.
Ticket Documentation
Flip cardThe practice of recording clear, specific details about a user's issue in a ticketing system to support efficient troubleshooting and historical tracking.
- Vague tickets slow down resolution
- Details should include symptoms, error messages, and steps taken
- Good documentation supports knowledge base creation
Memory trick: Details Drive Direction: gather info before you fix.
Driver Conflict BSOD (Third-Party Security Software)
Flip cardA blue screen caused by a newly installed driver, commonly from security software, that conflicts with the OS kernel; often resolved by uninstalling the software in Safe Mode.
- Safe Mode loads only essential drivers, isolating the faulty one
- Timing correlation with a recent install is a key diagnostic clue
- KERNEL_SECURITY_CHECK_FAILURE often points to a corrupted or conflicting driver
Memory trick: Safe Mode works = the new antivirus driver is the troublemaker
Windows Editions and Group Policy
Flip cardDifferent editions of Windows offer varying levels of features, with Pro, Enterprise, and Education editions supporting advanced management capabilities like joining an Active Directory domain and receiving Group Policy Objects (GPOs).
- Windows Home editions do not support Active Directory domain join.
- Group Policy provides centralized configuration and management of OS settings.
- GPOs are critical for enterprise security and compliance.
Memory trick: PRO for 'PROfessional' management, HOME for 'HOuSehold' use.
macOS Console
Flip cardA macOS utility that allows users and administrators to view, filter, and manage log messages generated by the operating system, applications, and services.
- Essential for troubleshooting system errors and application crashes.
- Provides real-time streaming of log entries.
- Can filter logs by process, message type, and time interval.
Memory trick: For system messages, check the Console.
Humidity and ESD Risk
Flip cardLow relative humidity in a server room increases the likelihood of electrostatic discharge, which can damage sensitive electronic components.
- Ideal data center humidity is typically 40-60%
- Low humidity = higher static electricity risk
- High humidity = condensation and corrosion risk
Memory trick: Dry air sparks; wet air rusts.
Tailgating
Flip cardA social engineering technique where an unauthorized individual follows an authorized person through a secured door to gain physical access without credentials.
- Also called piggybacking
- Prevented by mantraps and access-control awareness
- Exploits human courtesy (holding the door open)
Memory trick: Tailgating = sneaking in on someone's 'tail' through the door.
Battery Disposal
Flip cardDamaged or end-of-life lithium-ion batteries must be recycled at approved facilities due to fire risk and environmental hazards.
- Never puncture or crush a swollen battery
- Regular trash disposal violates e-waste regulations
- Follow SDS/local regulations for hazardous materials
Memory trick: Swollen battery? Recycle, don't trash it.
bootrec /fixmbr
Flip cardA Windows Recovery Environment command that writes a new master boot record compatible with Windows, commonly used to fix boot issues after installing another OS or bootloader.
- Run from the WinRE command prompt.
- Does not affect the boot sector or BCD directly.
- Often paired with bootrec /fixboot and /rebuildbcd for full repair.
Memory trick: 'Fix the MBR to Bring Windows Back'
bootrec /rebuildbcd
Flip cardA Windows Recovery Environment command that scans disks for Windows installations and rebuilds the Boot Configuration Data store used by BOOTMGR.
- Used when BOOTMGR is missing or BCD is corrupted
- Part of the bootrec.exe toolset
- Run from WinRE command prompt
Memory trick: Rebuild the BCD house from scratch when BOOTMGR vanishes
Physical Destruction
Flip cardMethods that physically damage storage media to ensure data is permanently unrecoverable.
- Highest level of data sanitization assurance.
- Includes shredding, pulverizing, incineration, and crushing.
- Irreversible process for data on HDDs, SSDs, and other media.
Memory trick: From simple delete to total destruction, choose wisely.
Mobile Hardware Diagnostics
Flip cardMobile devices often include built-in or accessible diagnostic tools to test various hardware components like screen, sensors, battery, and memory, helping to identify physical defects.
- Accessible via dialer codes (e.g., *#0*#) or specific apps.
- Tests components like display, touch, camera, sensors, speakers.
- Helps differentiate between hardware and software issues.
Memory trick: Test the parts before you wipe the slate.
MFA Factor: Something You Have
Flip cardAn authentication factor based on physical possession of an item, such as a smart card, security token, or authenticator app on a phone.
- Examples: smart card, hardware token, phone with authenticator app
- Combined with knowledge/biometric factors for MFA
- Lost item can be a security risk
Memory trick: Know it, Have it, Are it, Are-there it.
Startup Repair (WinRE)
Flip cardAn automated Windows Recovery Environment tool that scans for and fixes common problems preventing Windows from starting, such as corrupted boot files or BCD errors.
- Accessed via Advanced Startup Options or recovery media.
- Attempts fixes before manual tools like bootrec are needed.
- Does not erase user data.
Memory trick: 'Start with Startup Repair before Nuking the Drive'
Investigate and Verify Malware Symptoms
Flip cardThe first step in malware remediation is to research and confirm that a suspicious process, file, or behavior is actually malicious before acting.
- Malware often disguises process names to mimic legitimate Windows files
- Verification prevents accidental damage to legitimate system components
- This is step one of the seven-step malware removal best practices
Memory trick: 'I Quit Disks, Remediate, Schedule, Enable, Educate' — Investigate first!
Physical Destruction (for SSDs)
Flip cardA data destruction method that involves physically damaging the storage media (e.g., shredding, pulverizing, incineration) to ensure data is irretrievable.
- Most secure method for highly sensitive data on SSDs.
- Renders the drive unusable and data unrecoverable.
- Necessary for SSDs where software-based wipes or degaussing are ineffective.
Memory trick: For SSDs, shred it to truly delete it.
Background App Refresh
Flip cardA mobile OS feature that allows apps to update content in the background, which can cause increased battery and data usage if not managed.
- Can be disabled per-app in mobile OS settings
- Common legitimate cause of battery drain distinct from malware
- Should be checked before assuming an infection
Memory trick: One new app + battery drain = check background refresh first
Uninterruptible Power Supply (UPS)
Flip cardA UPS provides short-term battery backup power during outages, allowing systems time to save data and shut down safely.
- Protects against outages, not just spikes
- Provides limited runtime, not long-term power
- Often paired with surge protection features
Memory trick: UPS = 'Uninterrupted' means it keeps power flowing briefly.
APIPA (Automatic Private IP Addressing)
Flip cardA feature in Windows operating systems that automatically assigns a private IP address in the 169.254.0.0/16 range (169.254.0.1 to 169.254.255.254) when a DHCP server is unavailable.
- Indicates a failure to obtain an IP address from a DHCP server.
- Allows limited local network communication (within the same segment) but no internet access.
- Addresses are self-assigned, not manually configured or provided by a server.
Memory trick: 169.254: 'I Can't Connect' - it's an automatic red light for DHCP!
Process Masquerading
Flip cardA malware technique where a malicious process is named similarly to a legitimate system process to avoid detection by users and sometimes security software.
- Often involves subtle misspellings (e.g., 'svch0st.exe' for 'svchost.exe').
- Aims to blend in with legitimate system activity.
- Can consume high resources, cause instability, or exfiltrate data.
Memory trick: Malware hides by looking like legit, or staying low.
macOS Activity Monitor (CPU)
Flip cardA macOS utility that allows users to monitor and manage system resources, including the CPU usage of individual applications and background processes.
- Displays real-time CPU usage percentage for each process.
- Can be sorted to identify the highest CPU-consuming applications.
- Allows quitting unresponsive or resource-hogging processes.
Memory trick: Monitor activity to find the CPU hog.
Grandfather-Father-Son (GFS)
Flip cardA backup rotation scheme using daily, weekly, and monthly backup sets with tiered retention periods for efficient long-term storage management.
- Son = daily, Father = weekly, Grandfather = monthly
- Balances storage cost with historical recovery needs
- Common in enterprise backup strategies
Memory trick: Grandfather, Father, Son: three generations of backups.
Disk Defragmentation (Optimize Drives)
Flip cardA maintenance process that reorganizes fragmented data on mechanical hard drives so related file pieces sit contiguously, improving read/write speed.
- Only needed on HDDs, not SSDs
- Windows tool: Optimize Drives
- SSDs use TRIM instead of defrag
Memory trick: 'Defrag the Drag' on spinning disks.
Malware Containment
Flip cardThe first critical step in a malware removal process, which involves isolating the infected system from the network to prevent the malware from spreading to other systems, accessing external resources, or exfiltrating data.
- Prevents malware spread
- Stops data exfiltration
- Facilitates safe analysis and removal
- Often involves disconnecting from wired and wireless networks
Memory trick: Isolate the patient before you try to cure them, or they'll infect everyone!
Hot Aisle/Cold Aisle Containment
Flip cardA data center layout strategy that separates cool intake air from hot exhaust air by arranging racks in alternating aisles, improving cooling efficiency.
- Cold aisles face rack intakes, hot aisles face exhausts
- Reduces energy costs by preventing air mixing
- Part of environmental controls for equipment reliability
Memory trick: Keep hot and cold aisles apart like oil and water.
Rootkit Removal via Rescue Media
Flip cardRootkits hide from OS-level antivirus scans by operating at the kernel level; removal requires booting from external rescue media to scan the system offline.
- Rootkits evade in-OS antivirus detection
- Bootable rescue/USB antivirus media scans outside the OS
- Standard scans repeatedly reporting 'clean' is a red flag for rootkits
Memory trick: Rootkit roots deep underground — dig it out with rescue media from outside
Excessive App Permissions
Flip cardA mobile security red flag where an app requests permissions unrelated to its stated function, suggesting possible data harvesting or malicious intent.
- Compare requested permissions to the app's actual purpose
- Deny unrelated permissions or avoid installing the app
- Common tactic used by malicious/spyware apps disguised as simple utilities
Memory trick: Flashlight app asking for your contacts? Red flag flashing brightly
net use command
Flip cardA command-line utility in Windows used to connect to, disconnect from, and view network resources like shared folders and printers.
- Can map network shares as drive letters.
- Supports persistent connections ('/persistent:yes').
- Requires administrative privileges for some operations.
Memory trick: Net USE to CONNECT and manage network shares.
Windows Date & Time Settings
Flip cardA configuration area in Windows that allows users to adjust the system date, time, time zone, and set up automatic synchronization with internet time servers.
- Accessible via Control Panel or the Settings app.
- Crucial for correct timestamping of files and logs.
- Synchronization relies on Network Time Protocol (NTP).
Memory trick: DATE and TIME is where you SET the time.
XFS File System
Flip cardA high-performance journaling file system for Linux, known for its scalability, robust data integrity, and efficient handling of very large files and volumes.
- Designed for parallel I/O operations.
- Supports extremely large file and file system sizes.
- Commonly used in enterprise Linux for databases and high-throughput applications.
Memory trick: XFS is EXCELLENT for eXtreme data needs.
Driver Conflict BSOD (Third-Party Software)
Flip cardBSODs occurring immediately after installing new third-party software, especially security software, often indicate a driver conflict. Safe Mode is crucial for remediation.
- Common BSOD errors include 'DRIVER_VERIFIER_DETECTED_VIOLATION' or specific driver names.
- Boot into Safe Mode to prevent problematic drivers from loading.
- Uninstall the recently installed software or roll back its drivers.
Memory trick: New software, blue screen? Safe Mode's the scene!
ip addr show (Linux)
Flip cardA modern Linux command-line utility used to display information about network interfaces, including IP addresses, subnet masks, and status.
- Part of the 'iproute2' suite.
- Replaces the older 'ifconfig' command.
- Provides detailed network interface statistics.
Memory trick: IP ADDR SHOWs you all the address details.
Virtual Private Network (VPN)
Flip cardA secure, encrypted connection over a public network that allows remote users to access a private network and its resources.
- Creates a secure tunnel
- Allows access to internal network resources
- Encrypts data in transit
Memory trick: VPN is the key to the company's internal door.
Electrical Grounding
Flip cardProviding a low-resistance path for electrical current to flow to the earth, protecting against electrical shock and equipment damage.
- Crucial for electrical safety
- Diverts fault currents
- Prevents dangerous voltage buildup
Memory trick: Grounding: Your electrical safety net.
Get-Service Cmdlet
Flip cardA PowerShell cmdlet used to retrieve information about the services installed on a computer.
- Retrieves service status (running/stopped)
- Can filter by service name
- Part of PowerShell scripting
Memory trick: To see a service, you gotta Get it.
PowerShell Parameters
Flip cardVariables defined in a PowerShell script's 'param' block that accept input values when the script is run.
- Defined using 'param' block
- Can be mandatory or optional
- Allow for type checking and validation
Memory trick: Parameters are how scripts get their orders.
GPT (GUID Partition Table)
Flip cardA modern standard for the layout of the partition table on a physical hard disk, which is required for UEFI firmware and supports larger disk sizes and more partitions than MBR.
- Required for UEFI-based systems.
- Supports disks larger than 2TB.
- Allows for up to 128 primary partitions by default.
- Stores multiple copies of the partition table for redundancy.
Memory trick: UEFI needs GPT for a GREAT Partition Table.
Blanking Panels
Flip cardPanels used to fill unused spaces in server racks to prevent hot and cold air from mixing, improving cooling efficiency.
- Installed in server racks
- Crucial for data center cooling
- Prevents air recirculation
Memory trick: Cool racks need no gaps.
Change Advisory Board (CAB)
Flip cardA group of stakeholders responsible for reviewing, evaluating, and approving proposed changes to IT infrastructure to minimize risk and impact.
- Part of Change Management
- Reviews proposed changes
- Focuses on risk and impact assessment
Memory trick: Changes without a plan bring down the LAN.
mdsched.exe
Flip cardThe command-line executable for the Windows Memory Diagnostic tool, used to check for errors in the computer's Random Access Memory (RAM).
- Requires a system reboot to run.
- Performs various memory tests.
- Can identify hardware-level memory issues.
Memory trick: MD stands for Medical Doctor, and they CHECK your health (memory).
NTFS vs. Share Permissions
Flip cardNTFS permissions control access to files and folders both locally and over the network, while Share permissions control access only when files are accessed over a network share. When both are applied, the most restrictive permission takes precedence.
- NTFS: Local and network access; granular control.
- Share: Network access only; less granular.
- Most restrictive permission wins when both are applied.
Memory trick: NTFS is the key, Share is the door, most restrictive wins the war.
Smishing
Flip cardA form of social engineering that uses SMS text messages to trick individuals into divulging personal information or clicking malicious links.
- Uses text messages (SMS)
- Often contains malicious links or requests for data
- Aims to exploit trust or urgency
Memory trick: Don't get hooked by texts, calls, or emails!