Home › Certifications › CompTIA A+ › Core 2 — Operational Procedures
56 multiple-choice questions and 36 flashcards on Core 2 — Operational Procedures, about 10% of the CompTIA A+ bank. Every one carries a written rationale.
Core 2 — Operational Procedures is one of 9 chapters in CoStudy's CompTIA A+ bank, and it holds 56 of the bank's 540 multiple-choice questions — roughly 10% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
7 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
An acceptable use policy for AI tools should MOST directly address which of the following?
Answer: D — Disclosure of AI-generated content and no plagiarism
D) Correct — attribution, disclosure, and plagiarism rules are core to responsible AI use policy. A) Hardware sourcing is a procurement matter. B) Prompt length quotas are an implementation detail, not a policy principle. C) Language standards belong in development guidelines.
Which item is classified as PHI rather than ordinary PII?
Answer: D — A patient's lab results linked to their name and birth date
D) Correct — health information tied to an identifiable individual is protected health information. A) A mailing address is personally identifiable but carries no health context. B) A badge number identifies an employee without health data. C) Business contact details are generally not sensitive personal data at all.
Which remote technology is designed specifically to carry PowerShell and management commands between Windows systems?
Answer: B — Windows Remote Management over HTTP or HTTPS
B) Correct — WinRM is the Windows implementation of the WS-Management protocol used for remote command and PowerShell remoting. A) SSH can now carry PowerShell but is not the Windows-native management transport. C) RDP provides an interactive desktop, not a command transport. D) A VPN provides network reachability, not a management protocol.
During an incident investigation, which data should be collected FIRST according to the order of volatility?
Answer: A — The contents of system memory and running process state
A) Correct — memory and running state are the most volatile and vanish on power loss, so they are captured first. B) Local disk logs persist across a reboot and come later. C) Archived media is the least volatile of these options. D) Files on a network share persist independently of the affected host.
Which is the CORRECT order in a formal change management process?
Answer: D — Request, analyze, get CAB approval, implement
The standard sequence is request, risk and impact analysis, change advisory board approval, scheduling, implementation with testing, and documented outcomes. The other orders either implement before approval or document at the wrong point.
What is the BEST practice for ESD protection when handling internal computer components?
Answer: C — Wear a grounded anti-static strap and avoid carpet
C is right because a wrist strap holds the technician continuously at the same potential as the equipment ground, which is the only method that drains charge for the whole job. A and B both describe materials that generate static rather than dissipate it. D is backwards: motion against fabric and carpet is what creates the charge. E does equalize potential once, but the charge rebuilds as soon as you move, so it is a stopgap rather than the best practice.
Which backup rotation scheme keeps daily, weekly, and monthly sets so that older recovery points remain available for months?
Answer: B — Grandfather-father-son media rotation across three tiers
B) Correct — grandfather-father-son maintains monthly, weekly, and daily sets, preserving long-range restore points. A) A simple FIFO pool overwrites the oldest media and loses history. C) Continuous protection captures fine-grained recent changes but is not a rotation scheme. D) Mirroring copies current state and offers no historical versions.
4 cards from the 36 in this chapter.
What is post-incident review (PIR)?
After a major incident — what happened, root cause, what worked, what didn't, action items. Drives continuous improvement and prevents recurrence.
What is the importance of testing backups?
An untested backup is not a backup — restore tests verify integrity, completeness, and procedural readiness. Schedule periodic drills.
What is the difference between an SLA and an MOU?
SLA: contractual service-level commitments (uptime, response). MOU: less formal mutual understanding between parties. Both define expectations.
What is GDPR and why does it matter to IT?
EU privacy regulation. Requires lawful basis for processing PII, breach notification (72h), consent, data subject rights. Applies to anyone processing EU residents' data.
These are a sample. The full Core 2 — Operational Procedures chapter runs 92 items with per-chapter progress tracking, on the web and in the iOS app.