15 real 220-1101 sample questions, each with a worked explanation and a rationale for every option, right and wrong. No account, no card. This is the reasoning the 220-1101 tests: knowing why the tempting answer is wrong, not just spotting the right one.
The real 220-1101 is Maximum of 90 questions questions in 90 minutes, pass mark 675 / 900. For a domain-by-domain breakdown and a study plan, read the 220-1101 study guide. The full bank has 299 questions.
lock_openFree sampleHardware and Network Troubleshootingmedium
Priya reports that her Android phone, which comfortably lasted all day last month, now drops from full charge to flat by mid-afternoon even though her usage has not changed. Which action should a technician take FIRST to isolate the cause?
- AReview the built-in battery usage statistics to identify which app or service is drawing the most power.check_circle Correct
- BReplace the battery straight away, because a sudden change in runtime always means the cell has reached its charge-cycle limit.
- CPerform a full factory reset to clear any rogue background process that might be consuming the battery.
- DTurn off the Bluetooth and Wi-Fi radios and then watch whether the phone's battery life returns to normal.
When diagnosing sudden battery drain on a mobile device, identify the offending app or service using battery usage data before swapping hardware or wiping data. Battery usage statistics attribute power draw to specific apps and services, so they isolate the true cause first; replacing the battery or resetting the device acts before the problem is identified and can be both unnecessary and destructive.
Why A is correct: Correct: the battery usage screen breaks consumption down per app and service, letting the technician identify the problem before acting, which matches the first CompTIA troubleshooting step of identifying the problem.
Why B is wrong: Tempting because an ageing cell is a real cause of drain, but swapping hardware before any diagnosis skips the identify-the-problem step, and the absolute claim that it is 'always' the cell ignores common software causes.
Why C is wrong: Tempting because a reset can clear a misbehaving app, but it is destructive to the user's data and is applied before the offending process has even been identified, so it is far too aggressive as a first step.
Why D is wrong: Tempting because idle radios do use power, but this tests one narrow theory before a cause has been established and radios are rarely the sole driver of a sudden doubling in drain, so it is premature.
lock_openFree sampleHardware and Network Troubleshootingmedium
Aisha's tablet keeps dropping its Wi-Fi connection every few minutes in the far meeting room but stays connected reliably near the access point. Other users report the same drops on their devices in that same room. What is the MOST likely cause?
- AA failing wireless radio inside Aisha's tablet that keeps losing its association with the access point at random.
- BWeak signal from distance and obstructions in that room, dropping the connection whenever strength falls below a usable level.check_circle Correct
- CAn incorrect saved Wi-Fi passphrase that the tablet re-prompts for each time it tries to roam between channels.
- DDHCP scope exhaustion on the router that is handing out duplicate IP addresses to clients in the meeting room.
Intermittent Wi-Fi that is confined to one distant area and affects all devices there points to weak signal and coverage, not to a single client's hardware or configuration. IEEE 802.11 links degrade as distance and physical obstructions attenuate the signal, so when connectivity fails only in a far room and for every device there, marginal received signal strength is the common factor, not a per-device fault.
Why A is wrong: Tempting because a faulty client radio does cause intermittent drops, but every device in that room is affected equally, which rules out a fault confined to one tablet's hardware.
Why B is correct: Correct: the fault is tied to one distant location and affects every device there, which points to marginal signal strength and coverage rather than any single client, credential, or addressing problem.
Why C is wrong: Tempting because saved-credential errors do break Wi-Fi, but a wrong passphrase blocks authentication entirely rather than allowing a connection that repeatedly drops, so the symptom does not fit.
Why D is wrong: Tempting because address conflicts do disrupt connectivity, but DHCP exhaustion would affect clients regardless of where they sit, not just in one distant room, so it cannot explain the location-specific pattern.
lock_openFree sampleHardware and Network Troubleshootingmedium
Tom's phone has become completely unresponsive to touch, yet the display still shows the lock screen and notifications keep arriving. He has not dropped the device or exposed it to liquid. What should the technician try FIRST?
- ASend the phone away for digitiser replacement, since an unresponsive touchscreen points to failed touch-sensing hardware.
- BPerform a factory reset to wipe the corrupt configuration that is presumed to be blocking all touch input.
- CPerform a forced restart of the phone to clear a temporary software or driver hang before assuming hardware failure.check_circle Correct
- DRecalibrate the touchscreen through the accessibility menu, navigating the settings with the volume buttons as a workaround.
For a suddenly unresponsive touchscreen with a working display, try a forced restart to clear a software hang before assuming digitiser failure or wiping the device. A touch driver or foreground process can stall while the display continues to render, so a forced restart reloads the software stack and restores touch without data loss, making it the correct low-risk action before any hardware swap or reset.
Why A is wrong: Tempting because a dead digitiser does stop touch input, but committing to a hardware repair before ruling out a software hang is premature and costly, and the display and notifications still working suggests the device is otherwise healthy.
Why B is wrong: Tempting because a reset clears software faults, but it destroys the user's data and is far too drastic before a simple restart has even been attempted, so it is the wrong first move.
Why C is correct: Correct: a forced restart clears a frozen touch driver or stalled process in seconds without data loss, and it is the low-risk first action when the screen still displays content and receives notifications normally.
Why D is wrong: Tempting because recalibration can fix inaccurate touch, but most modern phones expose no such calibration menu, and it does nothing for a fully frozen screen, so it is not a reliable first step.
Hardware (25% of the exam)
lock_openFree sampleHardwaremedium
Priya is running a new data drop from a switch to a workstation that must support a 1 Gbps Ethernet link. She needs to terminate the twisted-pair cable with the correct plug. Which connector should she crimp onto the cable?
- ARJ-11, the six-position plug commonly used to terminate copper runs feeding desktop network adapters
- BRJ-45, the eight-position plug that terminates the four twisted pairs of an Ethernet patch or drop cablecheck_circle Correct
- CF-type, the threaded coaxial connector used to terminate the run and land it on the workstation adapter
- DDB-9, the nine-pin serial connector often crimped onto twisted-pair runs feeding network ports
Gigabit Ethernet over twisted pair is terminated with an eight-position RJ-45 connector, not the six-position RJ-11 telephone plug. Gigabit Ethernet transmits over all four twisted pairs, and only the 8P8C RJ-45 connector lands all eight conductors; RJ-11 exposes just the centre positions used for telephony.
Why A is wrong: RJ-11 is tempting because it looks like a smaller Ethernet plug and uses the same crimp tooling, but it is a 6-position telephone connector and will not carry a Gigabit Ethernet link.
Why B is correct: RJ-45 is an 8P8C connector that lands all four pairs, which Gigabit Ethernet requires, making it the correct plug for a 1 Gbps drop.
Why C is wrong: F-type is plausible from cable-modem work, but it terminates 75-ohm coaxial cable, not twisted pair, so it cannot terminate an Ethernet drop.
Why D is wrong: DB-9 is a legacy serial connector for consoles and peripherals, not a crimp-on Ethernet plug, so it cannot terminate a network drop.
lock_openFree sampleHardwaremedium
Dev must run a 300 metre network link between two buildings, and the path passes close to industrial motors that generate heavy electromagnetic interference. He wants a cable type that both spans the distance and is immune to that interference. Which cable best meets both requirements?
- ACat 6 unshielded twisted pair, which supports high speeds and easily reaches the full 300 metre distance
- BRG-6 coaxial cable, whose shielded conductor blocks interference and carries the signal across the 300 metre gap
- CFibre optic cable, which carries the signal as light and is inherently immune to electromagnetic interferencecheck_circle Correct
- DCat 5e shielded twisted pair, which adds foil shielding so the copper run reaches the full 300 metres
Fibre optic carries data as light, giving it immunity to electromagnetic interference and reach far beyond the 100 metre limit of copper Ethernet. Copper twisted pair is limited to about 100 metres and its conductors couple with nearby magnetic fields; fibre uses light in a glass core, so it is unaffected by EMI and spans hundreds of metres.
Why A is wrong: Cat 6 is tempting for its speed, but copper Ethernet is limited to roughly 100 metres per run and its unshielded pairs are susceptible to the motor interference.
Why B is wrong: RG-6 is shielded, which addresses interference, but it is a coaxial media for video and cable-modem service, not a building-to-building Ethernet backbone at this distance.
Why C is correct: Fibre transmits light through glass, so it neither radiates nor picks up electromagnetic interference and easily exceeds 100 metres, meeting both requirements.
Why D is wrong: Shielded Cat 5e resists interference better than UTP, but it is still copper Ethernet capped near 100 metres, so it cannot span 300 metres.
lock_openFree sampleHardwaremedium
Noah has a laptop with a single USB-C port that carries a Thunderbolt 3 signal. He wants to drive two external 4K displays and connect an external SSD enclosure through one cable to a dock. Which characteristic of Thunderbolt 3 makes this single-cable setup possible?
- AIt is a proprietary connector shape that only fits Thunderbolt docks and rejects standard USB-C plugs
- BIt reserves its whole bandwidth for video, so displays work but attached storage must use a separate port
- CIt converts the link to HDMI internally, which is why it can reach two 4K screens from one port
- DIt carries PCI Express and DisplayPort over one USB-C cable, so a dock can fan out to displays and storagecheck_circle Correct
Thunderbolt 3 tunnels PCI Express and DisplayPort over a USB-C connector, letting one cable and dock serve displays and high-speed storage together. Thunderbolt 3 uses the USB-C form factor but adds PCIe and DisplayPort protocol tunnelling at up to 40 Gbps, so a single link can be split by a dock into multiple displays and PCIe-based peripherals.
Why A is wrong: Thunderbolt 3 uses the USB-C connector shape and accepts USB-C plugs, so the premise of a unique physical connector is wrong.
Why B is wrong: This sounds cautious, but Thunderbolt 3 multiplexes data and video together, so storage and displays share the one link rather than needing separate ports.
Why C is wrong: Thunderbolt 3 carries DisplayPort, not HDMI, natively, so the HDMI-conversion explanation is incorrect even though multi-display output is real.
Why D is correct: Thunderbolt 3 tunnels PCIe and DisplayPort across a single USB-C link, letting one dock connection drive multiple displays and PCIe storage at once.
lock_openFree sampleNetworkingmedium
Which statement correctly distinguishes TCP from UDP as transport-layer protocols?
- ATCP is connection-oriented and uses a three-way handshake to provide ordered, reliable delivery, whereas UDP is connectionless and sends datagrams without acknowledgement.check_circle Correct
- BUDP opens a session with a three-way handshake and retransmits any lost segments, while TCP sends datagrams with no acknowledgement.
- CBoth TCP and UDP guarantee reliable in-order delivery and differ only in the range of well-known port numbers each is allowed to use.
- DTCP is connectionless and therefore faster for streaming, while UDP is connection-oriented and resends any packets that fail to arrive at the receiver.
Recognise that TCP is connection-oriented and reliable while UDP is connectionless and unacknowledged. TCP performs a three-way handshake and uses sequence numbers, acknowledgements, and retransmission to deliver an ordered, reliable byte stream. UDP omits all of that, sending independent datagrams with lower overhead but no delivery guarantee.
Why A is correct: TCP sets up a session and guarantees ordered delivery with acknowledgements and retransmission, while UDP is a lightweight connectionless protocol that trades reliability for speed.
Why B is wrong: This is tempting because both protocols are real transport protocols, but the attributes are reversed: the handshake and retransmission belong to TCP, not UDP.
Why C is wrong: This sounds reasonable because both use the same well-known port space, but only TCP guarantees reliable ordered delivery; UDP makes no such guarantee.
Why D is wrong: The connectionless-versus-connection-oriented labels are swapped here: UDP is the connectionless one, and TCP is the protocol that resends lost packets.
lock_openFree sampleNetworkingmedium
A web application must serve pages over an encrypted TLS session. Which well-known port and protocol does the browser connect to by default?
- ATCP port 80, the default for unencrypted HTTP traffic between the browser and web server.
- BTCP port 443, the registered port for HTTPS, which wraps HTTP inside a TLS-encrypted session.check_circle Correct
- CTCP port 8080, a common alternative that web proxies and application servers use for HTTP.
- DTCP port 21, the control channel a client opens when transferring files to a server.
Map HTTPS to TCP port 443 and distinguish it from plaintext HTTP on port 80. HTTPS is HTTP carried inside a TLS session, and IANA registers it on TCP port 443. Plaintext HTTP uses port 80, so only 443 provides the encrypted transport the application requires.
Why A is wrong: Port 80 is genuinely used for web traffic, but it carries plaintext HTTP with no TLS encryption, so it does not meet the encrypted requirement.
Why B is correct: HTTPS is registered on TCP port 443 and encapsulates HTTP within TLS, which is exactly what an encrypted web session requires.
Why C is wrong: Port 8080 is a real alternate HTTP port, but it is unregistered for TLS and still typically serves unencrypted traffic, so it is not the default for a secure session.
Why D is wrong: Port 21 is the FTP control channel, not a web protocol, so it is unrelated to serving encrypted web pages.
lock_openFree sampleNetworkingmedium
An administrator wants an encrypted command-line replacement for Telnet when managing a networking device. Which protocol and port provide that secure alternative?
- ATelnet on TCP port 23, which offers a familiar interactive command-line session to the device.
- BRDP on TCP port 3389, which gives an encrypted remote session to the target system.
- CSSH on TCP port 22, which encrypts the entire interactive command-line session and its credentials.check_circle Correct
- DHTTPS on TCP port 443, which encrypts the management traffic exchanged with the device.
Select SSH on TCP port 22 as the encrypted command-line replacement for insecure Telnet. SSH encrypts the full interactive session, including login credentials, and listens on TCP port 22. Telnet on port 23 sends everything in cleartext, so SSH is the best-practice secure command-line alternative.
Why A is wrong: Telnet on port 23 does give a command-line session, but it transmits credentials and data in plaintext, so it is the insecure protocol being replaced.
Why B is wrong: RDP is encrypted, but it provides a graphical desktop session rather than the command-line access that replaces Telnet.
Why C is correct: SSH on port 22 encrypts the whole session including authentication, making it the standard secure replacement for plaintext Telnet.
Why D is wrong: HTTPS is encrypted, but it serves a web management interface rather than the interactive command line that Telnet provides.
lock_openFree sampleMobile Devicesmedium
A technician is ordering replacement memory for a laptop that uses DDR4 SODIMM modules. How many pins does a standard DDR4 SODIMM have?
- A260 pins, the standard edge-connector count used by DDR4 laptop memory modulescheck_circle Correct
- B204 pins, the standard edge-connector count used by DDR3 laptop memory modules
- C240 pins, the standard edge-connector count used by DDR3 desktop memory modules
- D288 pins, the standard edge-connector count used by DDR4 desktop memory modules
Recognise that a DDR4 SODIMM uses 260 pins, distinguishing it from DDR3 SODIMMs and from desktop DIMM pin counts. SODIMMs are the compact memory form factor used in laptops, and JEDEC assigns each generation a distinct pin count so incompatible modules cannot seat; DDR4 SODIMM is standardised at 260 pins while DDR3 SODIMM is 204.
Why A is correct: Correct: JEDEC defines the DDR4 SODIMM with a 260-pin edge connector, distinct from the DDR3 SODIMM and from desktop DIMMs.
Why B is wrong: Tempting because 204 is a genuine SODIMM pin count, but it belongs to DDR3 SODIMM, not DDR4, so it is the wrong generation.
Why C is wrong: Tempting as a real DDR3 pin count, but 240 pins is a full-size desktop DIMM, not the smaller laptop SODIMM form factor.
Why D is wrong: Tempting because 288 is the correct DDR4 count, but it applies to the full-size desktop DIMM, not the laptop SODIMM.
lock_openFree sampleMobile Devicesmedium
A technician reads that a laptop accepts an M.2 2280 solid-state drive. What do the digits in the designation 2280 describe?
- AA drive that is 22 mm long and 80 mm wide, giving its overall board footprint
- BA drive that is 22 mm wide and 80 mm long, giving its overall board footprintcheck_circle Correct
- CA drive rated for 2280 MB/s of sequential throughput on the PCIe bus
- DA drive using 22 pins for data and 80 pins for power on its edge connector
Interpret an M.2 size code such as 2280 as width in millimetres followed by length in millimetres, not a speed or pin count. The M.2 specification names modules by physical dimensions so a board slot and standoff can be matched to the card; the first two digits are the fixed 22 mm width and the trailing digits are the length, here 80 mm.
Why A is wrong: Tempting because it uses the right numbers, but it reverses them: the first pair is the width and the second the length, not the other way round.
Why B is correct: Correct: in an M.2 size code the first two digits are the width in millimetres and the remaining digits the length, so 2280 is 22 mm by 80 mm.
Why C is wrong: Tempting because M.2 NVMe drives quote throughput figures, but the 2280 code is a physical size, not a speed rating.
Why D is wrong: Tempting because M.2 connectors do have defined pin layouts, but the 2280 code describes dimensions, not a pin split.
lock_openFree sampleMobile Devicesmedium
A technician is comparing two M.2 solid-state drives with identical 2280 dimensions, one an M.2 SATA drive and one an M.2 NVMe drive. Which statement about their interfaces is accurate?
- AThe SATA drive communicates over PCIe lanes and can exceed the roughly 6 Gb/s ceiling that the NVMe drive is bound by
- BBoth drives communicate over the SATA III interface, so their maximum throughput is identical despite the different labels
- CThe NVMe drive communicates over PCIe lanes and can exceed the roughly 6 Gb/s ceiling that the SATA drive is bound bycheck_circle Correct
- DBoth drives communicate over PCIe lanes, so the SATA label refers only to the command set and not the physical link
Distinguish M.2 SATA from M.2 NVMe by interface: SATA is capped near 6 Gb/s while NVMe rides PCIe lanes for higher bandwidth. An M.2 slot can carry either a SATA or a PCIe/NVMe signal, so identical-looking cards can differ greatly; NVMe uses PCIe lanes for far more bandwidth than the roughly 6 Gb/s SATA III ceiling that binds M.2 SATA drives.
Why A is wrong: Tempting as a near-mirror of the truth, but it swaps the interfaces: SATA is the one capped near 6 Gb/s and NVMe is the one on PCIe.
Why B is wrong: Tempting because both share the M.2 slot, but only the SATA variant uses SATA III; the NVMe variant runs on PCIe and is faster.
Why C is correct: Correct: M.2 NVMe drives use PCIe lanes with much higher bandwidth, while M.2 SATA drives are limited to the SATA III interface ceiling near 6 Gb/s.
Why D is wrong: Tempting because the slot is shared, but an M.2 SATA drive genuinely uses the SATA bus, not PCIe lanes.
lock_openFree sampleVirtualization and Cloud Computingmedium
Priya, a malware analyst, needs to run suspected malicious samples on her Windows laptop without letting them reach the host operating system or the corporate network. Which client-side virtualization use case does this describe?
- AA test-bed VM, a snapshot-based clone used to trial application patches before rolling them out across production desktops.
- BApplication virtualization, which streams a packaged app to the desktop so it runs without a local install or a full guest OS.
- CA cross-platform VM, used mainly to run a different operating system such as Linux alongside the Windows host for compatibility.
- DA sandbox, an isolated virtual machine used to detonate and observe untrusted code without exposing the host or production systems.check_circle Correct
Recognise that a sandbox is an isolated virtual machine used to safely run and observe untrusted or malicious code away from the host. A sandbox VM is deliberately isolated from the host and network so that code executed inside it, including malware, cannot escape to damage the physical machine or reach production systems, which is exactly what safe sample analysis requires.
Why A is wrong: Patch testing is a legitimate VM use, but its goal is validating updates, not deliberately containing hostile code, so it does not describe malware isolation.
Why B is wrong: App virtualization isolates one application from the host filesystem, but it shares the host kernel and is not built to safely detonate live malware.
Why C is wrong: Running a second OS for compatibility is a common VM benefit, but it says nothing about isolating and studying malicious samples, which is the stated need.
Why D is correct: A sandbox is a disposable, isolated VM whose whole purpose is to contain untrusted or malicious code so it cannot affect the host or the wider network.
lock_openFree sampleVirtualization and Cloud Computingmedium
Lena tries to create a 64-bit virtual machine in her hosted hypervisor and gets an error that hardware virtualization is disabled. The CPU supports it but the feature is turned off. What is the correct place to enable it?
- AIn the system firmware (BIOS/UEFI), by enabling the Intel VT-x or AMD-V CPU virtualization extension.check_circle Correct
- BIn the guest operating system's Device Manager, by updating the driver for the virtual processor exposed to the VM.
- CIn the hypervisor's VM settings, by allocating additional virtual CPU cores to the affected virtual machine.
- DIn the Windows Features control panel, by turning on the built-in platform so the hosted hypervisor can start guests.
Know that CPU virtualization support (Intel VT-x or AMD-V) is enabled in BIOS/UEFI firmware, not inside the OS or hypervisor VM settings. Hardware-assisted virtualization relies on the Intel VT-x or AMD-V CPU extension, which is exposed and toggled by the motherboard firmware; if it is disabled in BIOS/UEFI the hypervisor cannot launch 64-bit guests regardless of OS or VM settings.
Why A is correct: CPU virtualization support (Intel VT-x or AMD-V) is a firmware setting; enabling it in BIOS/UEFI is what lets the hypervisor run hardware-assisted 64-bit guests.
Why B is wrong: Device Manager manages drivers inside an already-running guest, but the virtualization extension must be active before the guest can boot, so this cannot fix it.
Why C is wrong: Adding vCPUs is plausible tuning, but core count does not turn on the CPU's virtualization extensions, so the hardware-disabled error would persist.
Why D is wrong: A Windows platform feature is host software configuration, but the specific error is about the CPU extension being off, which lives in firmware not in Windows Features.
lock_openFree sampleVirtualization and Cloud Computingmedium
A small firm wants to consolidate several always-on server workloads onto one physical host for the best guest performance and lowest overhead, with no need for a general-purpose desktop on that machine. Which hypervisor choice fits best?
- AA Type 2 hypervisor installed on a desktop OS, so staff can also browse and use office apps on the same server hardware.
- BA Type 1 bare-metal hypervisor installed directly on the host, so guests run without an intervening host operating system.check_circle Correct
- CApplication virtualization, streaming each server program to the host so no full guest operating systems are needed at all.
- DA container runtime sharing the host kernel, because that removes the hypervisor layer entirely for maximum density.
Select a Type 1 bare-metal hypervisor for dedicated server consolidation where lowest overhead and direct hardware access matter most. Because a Type 1 hypervisor installs directly on the hardware with no host OS layer, guest VMs get more direct access to CPU, memory, and I/O, delivering better performance and lower overhead than a hosted Type 2 product for dedicated server consolidation.
Why A is wrong: A hosted hypervisor is convenient for a workstation, but the intervening host OS adds overhead and is second-best when raw guest performance on dedicated hardware is the goal.
Why B is correct: A Type 1 hypervisor runs on bare metal with no host OS beneath it, giving guests more direct hardware access and lower overhead, ideal for consolidating server workloads.
Why C is wrong: App streaming isolates single programs, but consolidating full always-on server workloads needs complete guest VMs, which application virtualization does not provide.
Why D is wrong: Containers are dense, but they share one kernel and are not the hypervisor-based full-VM consolidation the scenario describes for mixed server operating systems.
Examworthy is not affiliated with or endorsed by CompTIA. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. 220-1101 and related marks belong to their respective owners.