CompTIA · 220-1102
CompTIA A+ Core 2 validates foundational IT support skills in operating systems, security, software troubleshooting, and operational procedures. It is the second of two exams required to earn the CompTIA A+ certification, the industry-standard credential for entry-level IT support roles.
Practice Questions
700
≈ 7 practice exams
Duration
90 minutes
Passing Score
700/900
Difficulty
FoundationalLast Updated
Mar 2026
Use this 220-1102 practice exam to prepare for CompTIA A+ Core 2 (220-1102) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 700 questions for CompTIA 220-1102, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Operating Systems (Windows, macOS, Linux), Security, Software Troubleshooting, Operational Procedures, and Mobile Device Management. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
CompTIA A+ Core 2 (220-1102) is the second exam required to earn the CompTIA A+ certification, the industry standard credential for entry-level IT professionals. This exam validates essential skills in operating systems (Windows, macOS, Linux), security practices, software troubleshooting, and operational procedures. Core 2 focuses on the software and management aspects of IT support, complementing Core 1's hardware and networking emphasis. Together, these two exams demonstrate foundational competency in supporting end-users and maintaining IT infrastructure, making this certification a critical credential for anyone pursuing a career as an IT support specialist or help desk technician.
The CompTIA A+ Core 2 exam targets entry-level IT professionals seeking to validate their foundational support skills. Ideal candidates include help desk technicians, IT support specialists, junior system administrators, and field service technicians with hands-on experience in IT support roles. CompTIA recommends candidates have 12 months of hands-on experience in an IT support specialist role before attempting the exam. This certification is also valuable for IT career changers, individuals transitioning from related technical fields, and professionals looking to advance into network administration, systems administration, or information security roles.
CompTIA recommends 12 months of hands-on experience working as an IT support specialist or in a similar IT support role before attempting the Core 2 exam. While there are no formal prerequisites to register for the exam, CompTIA suggests candidates should be comfortable with troubleshooting common PC hardware and software issues. Many organizations recommend passing Core 1 (220-1101) first, as the two exams together provide comprehensive coverage of foundational IT competencies. Candidates should be familiar with major operating systems, basic security concepts, and IT service management principles to maximize their chances of success.
CompTIA A+ Core 2 is delivered as a 90-minute computer-based exam with a maximum of 90 questions. The exam includes multiple-choice questions (both single and multiple response), drag-and-drop questions, and performance-based questions that simulate real-world IT scenarios. Candidates must achieve a minimum score of 700 on a scale of 100-900 to pass. The exam can be taken online or at Pearson VUE testing centers. There may be unscored survey questions included as CompTIA gathers data for exam development, but these do not affect the final score.
The CompTIA A+ certification, earned by passing both Core 1 and Core 2, is recognized as the industry-standard entry-level credential for IT support professionals and is required or preferred by many employers and government agencies, including the U.S. Department of Defense. A+ certified professionals typically earn between $49,000 and $80,500 annually, with top earners exceeding $100,000 depending on experience, location, and specialization. The certification serves as an excellent launching pad for career advancement, with A+ holders frequently advancing to junior system administrator, network administrator, IT technician specialist, or information security positions. Stacking additional certifications such as CompTIA Network+ or Security+ alongside A+ significantly increases market value, with potential salary increases of $10,000-$15,000 annually when combined with cloud certifications.
5 sample questions with answers and explanations. The full bank has 700 questions, enough for 7 full-length practice exams.
Preview — answers shown1. A company is implementing a new AI-powered chatbot to assist the customer support team. The chatbot will process customer inquiries and generate responses. A manager asks the IT department which types of data should NEVER be entered into the public AI system. Which three types of data should be restricted from the public AI tool? (Select three!)
Multiple correct answersExplanation
Customer Social Security numbers and financial records, protected health information subject to HIPAA, and proprietary trade secrets must never be entered into a public AI system. Public AI tools process data on shared third-party cloud infrastructure where the organization has limited control over how data is stored, processed, or potentially used for model training. Social Security numbers and financial records are regulated under PCI DSS and privacy laws. Protected health information is regulated under HIPAA, and violations can result in significant fines. Trade secrets and intellectual property lose their legal protection once disclosed to a public system. General product specifications already available on the company website are public information and pose no risk. Publicly available industry news articles are already in the public domain. Company holiday schedules and office locations are non-sensitive operational information.
2. A systems administrator at Tailspin Toys needs to configure authentication for the company's web-based applications that are hosted by multiple third-party cloud providers. Employees should be able to log in once using their corporate credentials and access all authorized applications without re-entering passwords. The environment includes both Windows and non-Windows systems. Which of the following technologies should the administrator implement? (Select one!)
Explanation
SAML (Security Assertion Markup Language) is an XML-based protocol designed for exchanging authentication data between an identity provider and multiple service providers, enabling single sign-on across web-based applications including those hosted by third-party cloud providers. It works across both Windows and non-Windows environments. Kerberos is primarily used within Windows Active Directory domains and does not natively extend well to third-party cloud web applications. RADIUS is primarily used for network access authentication such as Wi-Fi and VPN, not web application SSO. TACACS+ is used for device administration authentication on network equipment like routers and switches.
3. A security team at Fabrikam Corp. discovers that employees have been scanning QR codes posted on flyers in the office break room. The QR codes redirect users to a convincing replica of the company's login portal, where credentials are harvested. Which type of social engineering attack is being described? (Select one!)
Explanation
QR code phishing, also known as quishing, uses malicious QR codes to redirect victims to fraudulent websites designed to harvest credentials or deliver malware. In this scenario, the attacker placed physical QR codes in a trusted location to trick employees into visiting a fake login page, which is the defining characteristic of a quishing attack. This attack vector is particularly dangerous because QR codes bypass traditional email security gateways and users often scan them with personal mobile devices that lack corporate security controls. An evil twin attack creates a fake Wi-Fi access point that mimics a legitimate wireless network to intercept traffic, which does not involve QR codes. Shoulder surfing involves physically observing someone entering credentials or viewing sensitive information on their screen. An on-path attack intercepts and potentially alters communication between two parties in transit over a network, which is fundamentally different from using QR codes to redirect users to a phishing site.
4. A systems administrator at Litware is deploying power protection for a rack of servers in the company's on-premises data center. The servers run a real-time transaction processing application that cannot tolerate any momentary loss of power, even for a few milliseconds, during utility power failures or voltage irregularities. Which UPS type should the administrator select to meet this requirement? (Select one!)
Explanation
A double-conversion (online) UPS provides zero transfer time because the connected equipment continuously runs on power that is regenerated through an AC-to-DC and DC-to-AC conversion process. The inverter is always active and the battery is always in the power path, so when utility power fails there is no switching delay whatsoever. A standby (offline) UPS monitors utility power and switches to battery only when an outage is detected, resulting in a brief transfer time typically ranging from 5 to 12 milliseconds during which equipment may experience a momentary power interruption. A line-interactive UPS includes an autotransformer for automatic voltage regulation and has a faster transfer time of approximately 2 to 4 milliseconds, but it still has a brief switchover gap that could affect sensitive real-time applications. A surge protector with battery backup is not a recognized UPS topology and would not provide the continuous, zero-interruption power delivery required for mission-critical transaction processing servers.
5. A systems administrator at Litware Corp. is implementing a backup strategy for the company's file server. The backup window is limited, and the administrator needs to minimize daily backup time and storage usage while accepting that restoring data may take longer if a disaster occurs. The strategy should include a full backup on Sunday nights. Which of the following backup schedules should the administrator implement for Monday through Saturday? (Select one!)
Explanation
Incremental backups back up only the data that has changed since the last backup of any type, resulting in the fastest backup times and smallest storage requirements for each daily backup. This is ideal when the backup window is limited. The trade-off is that restoring requires the last full backup plus every incremental backup in sequence, making restoration slower, which the scenario states is acceptable. Full backups every night would provide the fastest restoration but consume the most time and storage, exceeding the limited backup window. Differential backups back up all changes since the last full backup, growing larger each day and taking progressively longer throughout the week. Synthetic full backups are created by merging the existing full backup with incrementals on the backup server, which requires significant server-side processing and storage comparable to full backups.
CompTIA SecurityX (CAS-005)
CAS-005 · 599 questions
CompTIA Tech+ IT Fundamentals (FC0-U71)
FC0-U71 · 599 questions
CompTIA A+ Core 1 (220-1101)
220-1101 · 700 questions
CompTIA Cloud+ (CV0-004)
CV0-004 · 700 questions
CompTIA CloudNetX (CNX-001)
CNX-001 · 598 questions
CompTIA Cybersecurity Analyst+ (CySA+) (CS0-003)
CS0-003 · 700 questions
$17.99
One-time access to this exam