Reviewed 10 October 2026 against the linked published scope. V15 domains: operating systems 28%, security 28%, software troubleshooting 23%, operational procedures 21%.
Memory hook: Protect data, identify the boundary, make a reversible fix and verify with the user.
Read the essentials, cover the answers and explain the decision aloud. Open the topic summaries below whenever a distinction is unclear.
Operating systems and tools
- Choose the required OS edition, architecture and supported upgrade path. A clean install replaces an environment; an in-place upgrade preserves eligible apps/settings but still needs a recovery plan. Partition style, boot mode, filesystem and drivers must match the platform.
- Windows tools have distinct jobs: Task Manager examines running workload; Event Viewer logs; Device Manager hardware/drivers; Disk Management storage; Services background services; System Configuration startup diagnosis. Settings and Control Panel expose configuration.
ipconfig,ping,tracert,nslookupandnetstatseparate network faults.sfcand supported DISM repair operations address different Windows image/system-file issues. Review the exact command, impact and backup before repair.- NTFS permissions govern files; share permissions also apply over SMB. Effective access depends on both layers, group membership and deny rules. BitLocker encrypts storage and needs recovery-key handling; it does not replace access controls.
- macOS uses Finder, System Settings, Activity Monitor and Keychain; Linux uses filesystem paths, ownership/modes, package tools and services. Know
pwd,ls,cd,cp,mv,chmod,chown,ps,sudoand relevant help. Case sensitivity and installation models vary. - Android/iOS permissions, enrollment, app sources, updates, backup/sync and screen locks are part of device security. Removing an app is not always the same as revoking its cloud sessions or deleting retained data.
Security
- Apply least privilege, MFA, patches, secure Wi-Fi and protected recovery copies. Lock screens, separate admin and ordinary work, and protect physical access. A firewall filters traffic; anti-malware/EDR evaluates suspicious endpoint behavior.
- Phishing manipulates trust; social engineering can use phone, text or in-person requests. Verify unexpected sensitive requests through a known channel. Password length, uniqueness and a manager reduce reuse risk.
- Shared permissions, local accounts and cloud identities can independently grant access. Disable or remove access through the correct lifecycle process; preserve needed data and records before account changes.
- For malware: identify symptoms, isolate appropriately, follow the authorized remediation process, update/scans or rebuild from a trusted source, restore protections, validate and educate. Preserve evidence when incident procedures require it.
- Destroying, sanitizing or recycling media requires an approved method appropriate to sensitivity and technology. Formatting or ordinary deletion does not reliably sanitize every device.
Troubleshooting and professional practice
- A slow system may be constrained by CPU, RAM, storage, network, temperature or malicious activity. Establish a baseline and inspect evidence before reinstalling everything.
- After an update breaks an application, check version compatibility, logs, dependencies, drivers and available rollback. Safe Mode or a clean boot helps isolate components but is not automatically the permanent fix.
- Boot failures require separation of firmware/device detection, boot configuration and OS loading. Back up accessible data before risky repair. Application crashes, permission failures and network failures need different fixes.
- Document symptoms, scope, actions, results and user acceptance. Follow change approval, maintenance windows and rollback plans; inventory and diagrams must reflect the final system.
- Use ESD protection and electrical/battery safety. Lift correctly, manage cables and follow hazardous-material handling procedures. Obtain permission before viewing sensitive information or initiating remote access.
- Scripts automate repeat tasks but inherit caller permissions and can cause broad damage. Recognize shell, PowerShell and Python script purposes; inspect inputs, quoting, credential handling and the target scope before execution.
- Backups differ: full captures all selected data, incremental changes since the previous backup, differential changes since the last full. Restoration needs the corresponding chain and a verified recovery point.
Exam traps
- Synchronization can propagate deletion; it is not automatically a backup.
- Disabling a security control to make an application work hides the underlying permission or configuration issue.
- Respect confidentiality, communicate in plain language and confirm the original problem is fixed before closing the ticket.
Final active recall
1. A share permits change but NTFS permits only read. Can a network user edit?
Normally no: effective access must satisfy both applicable permission layers.
2. An application fails only during a normal boot. What can a clean boot reveal?
A startup service or program conflict; re-enable systematically to identify the cause.
3. What does an incremental restore typically require?
The relevant full backup plus each required incremental in the chain.
4. Why save a BitLocker recovery key separately?
A TPM, boot or hardware change may require recovery; the encrypted drive alone cannot supply usable access.
5. The user asks you to read an unrelated confidential file during support. What governs the action?
Authorized task scope, business need and privacy policy; technical access is not blanket permission.
Sources and further practice
- Official exam scope
- Objective-to-topic coverage map. Each full topic links to its supporting primary technical documentation.
Every topic at a glance
Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.
01 · Windows Installation, Filesystems and Recovery
Memory hook: Choose the supported path before changing the boot disk.
Must remember
Check hardware requirements, firmware/boot mode, edition, architecture, licensing, application compatibility and data backup before installing or upgrading. An in-place upgrade preserves supported settings/apps under its compatibility rules; a clean installation creates a fresh environment. Imaging and unattended deployment need correct drivers, identity and licensing handling.
GPT commonly pairs with modern UEFI boot; legacy MBR has different partition/size limits. NTFS supports Windows permissions and features; exFAT supports useful cross-platform removable storage; FAT32 has a 4 GiB single-file limit. Filesystem choice depends on device/OS compatibility and required security/recovery features.
Disk Management handles volumes, partitions, drive letters and supported conversions. BitLocker protects volumes; retain the recovery key in an approved location before firmware/TPM or disk changes. Encryption protects confidentiality, not against accidental deletion or all malware while the user is signed in.
Windows Recovery Environment offers tools for startup repair and recovery. Safe Mode loads a reduced environment for diagnosis. Restore points address supported system configuration changes, not a complete user-file backup. Reset/reinstall options differ in what they retain; verify the exact option before proceeding.
Use supported installation media and verify backups through restoration. Driver architecture/version, storage controller support, insufficient space, interrupted updates and firmware settings can each block installation or boot. Do not format a disk merely because an installer cannot see it; investigate the controller/driver path first.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Preserve supported apps/settings | A compatible in-place upgrade with backup. |
| Recover after a bad driver | Appropriate Safe Mode, rollback or restore/recovery tool. |
| Move large files between supported systems | Consider exFAT when its compatibility/security tradeoffs fit. |
Traps
- A restore point is not a full data backup.
- A BitLocker recovery prompt after firmware change does not necessarily mean the disk failed.
02 · Windows Administration and Command Tools
Memory hook: Pick the tool that exposes the failing layer.
Must remember
| Tool | Useful question |
|---|---|
| Task Manager / Resource Monitor | Which process or resource is busy? |
| Event Viewer | What happened, when and in which component? |
| Device Manager | Is a device/driver recognized and functioning? |
| Services | Is a service running and configured to start? |
| Disk Management | How are disks/volumes allocated and mounted? |
| Registry Editor | What low-level setting exists? Change only with a justified backup/plan. |
| System Information / msinfo32 | What hardware, firmware and system configuration is present? |
Command tools include ipconfig, ping, tracert, nslookup, netstat, hostname, whoami, gpupdate and gpresult. File/process tools include dir, copy, robocopy, tasklist and taskkill. Use the correct shell: Command Prompt and PowerShell have different syntax and object/pipeline behavior.
sfc checks protected system files; DISM services/repairs Windows images under the chosen options; chkdsk checks filesystem-related structures and can require disruptive repair. Understand the command's effect before running a repair switch. Read-only inspection should precede changes when evidence is needed.
Local accounts, domain identities and Microsoft Entra/work accounts have different authority and policy paths. Local groups and UAC affect privilege; elevating a process is not the same as granting every user administrator rights. Group Policy can enforce settings that local manual changes later lose.
Use logs, version information and recent changes to choose a fix. Protect sensitive output in support tickets and avoid copying secrets into commands, scripts or screenshots.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| One process consumes memory | Task Manager/Resource Monitor, then process-specific diagnosis. |
| Policy resets a local setting | Inspect applied policy and its management source. |
| Device fails after update | Device Manager, driver history and vendor compatibility. |
Traps
- Registry edits are not a universal first troubleshooting step.
- Administrative elevation does not repair an incorrect command or target.
03 · macOS, Linux and Mobile Operating Systems
Memory hook: Same support questions, different tools and permission models.
Must remember
macOS uses tools such as System Settings, Activity Monitor, Disk Utility, Keychain Access and Time Machine. Finder manages files; Terminal exposes a Unix shell. APFS supports modern macOS storage features. FileVault encrypts supported volumes; recovery access must be preserved. Application installation can use the App Store, packages or disk images with appropriate trust checks.
Linux distributions differ in package managers and defaults. ls, pwd, cp, mv, grep, find, chmod, chown, ps, top, df, ip and sudo expose common administration tasks. Package tools such as APT and DNF are not interchangeable commands. Permissions, ownership and service state can explain failures without reinstalling the OS.
Mobile OSs separate apps through permissions and sandboxing. Review app storage, updates, permissions, account synchronization, network settings and device-management policy. Location, camera and microphone permissions should match function. Sideloading, rooting/jailbreaking and untrusted profiles change the security assumptions.
Cross-platform support needs compatibility checks for file formats, drivers, filesystems, applications and identity. A file visible on one OS may have unsupported metadata or access semantics on another. Cloud synchronization can introduce conflicts, offline states and account-scope confusion.
Use supported update/recovery procedures and back up data before resets. Verify whether the device is personally owned or managed before removing profiles or accounts. An organization may enforce settings that a user cannot override locally.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Mac application consumes CPU | Activity Monitor and application evidence. |
| Linux user cannot read a file | Inspect path permissions/ownership and applicable security controls. |
| Managed mobile setting is unavailable | Check management policy and ownership before changing profiles. |
Traps
- A factory reset can destroy data and trigger activation/enrollment requirements.
- A successful sync icon does not prove an independent backup exists.
04 · Security Principles and Controls
Memory hook: Protect the right property with the right kind of control.
Must remember
Confidentiality prevents unauthorized disclosure; integrity protects against unauthorized alteration; availability keeps a service usable. Authenticity establishes that something is genuine. Non-repudiation supplies evidence of origin or action, subject to trustworthy keys, identities and records.
Authentication establishes an identity, authorization decides permitted actions and accounting records activity. Identify which stage failed: a valid login with excessive database privileges is an authorization problem.
| Classification | Examples |
|---|---|
| Technical | Firewall, encryption, access-control software. |
| Managerial | Policy, risk assessment, oversight. |
| Operational | Human-run procedures, training, guard processes. |
| Physical | Locks, barriers, cameras, environmental protection. |
| Preventive / detective / corrective | Block / discover / repair. |
| Deterrent / directive / compensating | Discourage / instruct / supply an alternative protection. |
One control can have several classifications. A camera detects; a visible camera may also deter. A compensating control addresses the original control's intent when the normal implementation is not feasible; it does not simply mean a cheaper control.
Zero trust evaluates access using identity, device state, resource sensitivity and context rather than trusting network location. A policy engine decides, a policy administrator arranges the session and an enforcement point permits or blocks it. Least privilege and segmentation reduce blast radius; continuous evaluation handles changing conditions.
Honeypots, honeynets, honeyfiles and honeytokens are deception tools. Access to a decoy can be a high-value detection signal, but a decoy needs containment and monitoring.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Prevent disclosure | Access control and encryption appropriate to the data path. |
| Find unauthorized changes | Integrity checks, signatures and audit evidence. |
| Legacy system cannot implement a mandated control | Evaluate an approved compensating control against the same risk. |
Traps
- Encryption alone does not make a service available.
- Zero trust is an architecture and decision process, not one appliance.
05 · Identity, Authentication and Privileged Access
Memory hook: Who are you, what may you do, and for how long?
Must remember
Factors are something you know, have or are. Two passwords are not MFA. Hardware-backed phishing-resistant authentication reduces risks that a phishable one-time code does not fully address. Biometrics need fallback and privacy controls; false acceptance and false rejection trade off against each other.
SSO reduces repeated sign-ins; federation lets one identity provider assert identity to another service. SAML carries assertions commonly used in enterprise federation. OAuth delegates authorization; OpenID Connect adds an identity layer. Kerberos uses tickets and depends on appropriate time synchronization. LDAP is a directory-access protocol, not encryption by itself.
RBAC grants access through roles; ABAC evaluates attributes and context; discretionary access lets owners delegate; mandatory access enforces centrally controlled labels. Least privilege restricts permissions; separation of duties prevents one person completing a sensitive workflow alone. Need-to-know narrows access even among sufficiently cleared users.
Provisioning must cover joiners, movers and leavers. Reconcile access after role changes and promptly revoke accounts, sessions, keys and tokens when required. Periodic access reviews find accumulated privilege and dormant accounts. Service accounts need ownership, scoped permissions and credential lifecycle controls too.
PAM manages privileged access with vaulting, approval, session recording and just-in-time elevation. Just-enough access narrows the permitted actions. A break-glass account needs controlled storage, monitoring and periodic tests; it should not become a daily shared login.
RADIUS commonly centralizes network access authentication; TACACS+ is often used for network-device administration with separable AAA functions. Certificates and device posture can supplement user identity. An authenticated user can still be compromised or unauthorized for the requested object.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Temporary production administration | Approved just-in-time privilege with logging. |
| Access depends on classification and device state | Attribute/context-based policy. |
| A user changes department | Reconcile old and new permissions, not only add the new role. |
Traps
- SSO without careful controls can concentrate compromise risk.
- Authentication success does not establish authorization for every resource.
06 · Hardening and Vulnerability Management
Memory hook: Inventory, prioritize, fix, verify.
Must remember
You cannot secure unknown assets. Maintain ownership, location, purpose, classification, versions and support status. Apply secure baselines: remove unused software/services, disable default accounts, restrict administration, patch, configure logging and enforce appropriate endpoint protection.
Mobile management can enforce encryption, screen lock, application policy and remote wipe. BYOD raises ownership/privacy boundaries; choose whole-device management versus application/container controls deliberately. Rooted/jailbroken devices weaken assumptions. Wireless, browser, email and document settings can expose different attack surfaces.
Vulnerability scanning identifies potential weaknesses; penetration testing attempts to demonstrate exploitability within authorization and rules of engagement. Credentialed scans can inspect more internal configuration. SAST examines code without running the application; DAST tests running behavior; software composition analysis identifies dependencies and known component issues.
Prioritize using exploitability, exposure, asset value, business impact and active exploitation, not severity alone. CVE identifies a known vulnerability; CVSS scores technical severity; threat intelligence adds context. A low-scoring flaw on a critical exposed identity system can deserve urgent action.
Remediation may mean patching, reconfiguration, removing a component or applying an approved compensating control. Exceptions need owners, expiration and risk acceptance. Test compatibility, maintain a rollback plan, deploy in controlled stages and rescan to verify the issue is resolved. Suppressing an alert is not remediation.
False positive: a reported issue that is not actually present. False negative: an existing issue missed by the test. Confirm with evidence before tuning detection. Sandboxing isolates suspicious code for analysis; a safe analysis environment should not have production access or usable production credentials.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Find missing updates at scale | Authenticated scanning with appropriate permissions. |
| Prove a finding’s impact | Authorized validation or penetration testing within scope. |
| Cannot immediately patch | Time-bound approved mitigation and tracked risk. |
Traps
- CVSS alone is not business risk.
- An uncredentialed scan may miss issues visible from inside the system.
07 · Malware and Endpoint Recovery
Memory hook: Contain, investigate, clean and prove trust again.
Must remember
Recognize suspicious behavior: unexpected browser redirects, disabled security tools, unknown persistence, unusual account activity, encrypted files or unexplained network traffic. Performance problems alone do not prove malware. Collect evidence and follow the incident procedure rather than running random cleanup tools.
Quarantine/isolate a suspected system as appropriate to protect others, preserving evidence when required. Update and use approved tools from a trusted environment. Safe Mode or offline scanning can help when the normal environment is unreliable. Remove persistence and entry points, not only the visible file.
Restore or rebuild from known-good sources when trust cannot be established. Verify backup integrity, patch the weakness, reset/revoke affected credentials and sessions, and re-enable protection. A restored infected backup or stolen live token can reintroduce compromise.
Browser security includes supported versions, trusted extensions, safe download handling and appropriate privacy settings. Clearing cache may fix stale content but does not revoke an attacker’s session or remove every malicious extension. Social-engineering recovery includes educating the user without blame and making reporting easy.
For ransomware or suspected data exposure, escalate to the authorized security/legal process. Do not promise that deleting malware means no data left the device. Document observed scope and uncertainty accurately.
Verify both technical health and the original user workflow. Monitor for recurrence, confirm backups and update the ticket/runbook with the established cause and prevention steps.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Potential active compromise | Follow authorized isolation/escalation and evidence procedures. |
| Cannot trust OS integrity | Controlled rebuild from known-good media and verified data. |
| Credentials may be stolen | Revoke/reset affected access through the appropriate identity process. |
Traps
- A malware scanner’s clean result is useful evidence, not absolute proof of trust.
- Deleting a suspicious file does not necessarily remove persistence.
08 · Application and OS Troubleshooting
Memory hook: Reproduce the symptom without destroying the evidence.
Must remember
Separate a single application, one user profile, the OS and shared services. Compare a working user/device and inspect recent updates, permissions, storage, dependencies and network paths. Record exact errors and timestamps; “it is slow” needs measurable context.
Crashes can involve application defects, incompatible extensions, corrupted profiles, missing runtimes, insufficient resources or hardware faults. Use Event Viewer/reliability data on Windows, platform logs elsewhere and safe vendor diagnostics. A clean boot/Safe Mode can isolate startup components, but restore the intended configuration afterward.
Boot loops and failed updates may require recovery tools, driver rollback, repair or restoration. Preserve data and recovery keys before destructive actions. A BSOD/stop error is evidence to investigate, not an instruction to reinstall immediately. Low disk space can block updates, paging and application writes.
Mobile issues include app permission denial, full storage, synchronization conflicts, network switching, battery optimization and management restrictions. Try scoped steps such as checking settings, updating/restarting the app and verifying the service before wiping the device.
Browser failures can originate in DNS, proxy, certificates/time, extensions, cached state or the remote service. Check whether other sites/users work and whether the issue occurs in a controlled clean profile. Do not teach users to bypass certificate warnings as a routine fix.
After repair, retest the same workflow, verify security controls and document changes. Escalate with useful evidence when the cause belongs to a backend service or application owner.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Only one profile affected | Investigate profile-specific settings and permissions. |
| All users fail simultaneously | Check shared service/network/change dependencies. |
| Certificate warnings suddenly appear | Check time, endpoint identity and trust chain before proceeding. |
Traps
- A reset can hide the cause while losing data.
- Disabling security permanently is not an acceptable generic performance fix.
09 · Support Processes, Safety and Communication
Memory hook: Get permission, explain clearly, leave a useful record.
Must remember
Tickets should record user/contact, affected asset, symptoms, scope, urgency/impact, evidence, actions, escalation and resolution. Priority depends on impact and urgency, not who complains loudest. Keep passwords, keys and unnecessary personal data out of tickets.
Change procedures include authorization, risk, testing, backup, rollback, maintenance timing and validation. Asset management tracks ownership, lifecycle and licenses. Knowledge articles should explain reproducible steps and prerequisites; version control helps maintain scripts/configuration.
Professional communication uses plain language, active listening and realistic expectations. Respect confidentiality, cultural differences and accessibility. Confirm authorization before remote control or sensitive data access; explain what you will do and when the session ends. Verify caller identity rather than trusting urgency.
Electrical, ESD, lifting, battery, chemical and fire hazards require the right procedure. Know where safety data sheets and emergency processes are found. Secure devices physically and follow approved disposal/recycling rules. Never open a hazardous power supply as routine field troubleshooting.
Licensing, prohibited content, evidence preservation and regulated data require escalation through policy. A technician should not investigate beyond authorized scope or make legal promises. Preserve relevant evidence and document actions when a security or legal incident is suspected.
Scripts can automate repetitive support tasks, but must validate inputs, scope targets, handle errors and protect secrets. Recognize common script types and execution policies; test on safe targets before broad use. AI assistance can help draft steps, but verify commands and never expose customer secrets to an unapproved service.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Request affects confidential files | Verify identity/authorization and minimize access. |
| High-impact outage | Prioritize by business impact and urgency with clear communication. |
| Repeatable support task | A reviewed, bounded script and documented verification. |
Traps
- A user’s urgency does not establish authorization.
- Technical access to a file does not mean permission to inspect it.
10 · Data Lifecycle, Privacy and Recovery
Memory hook: Know the owner, keep only what you need, test restoration.
Must remember
Classify data by business impact and obligations, then label and protect it consistently. Owners decide use/classification; custodians implement handling. Controllers determine processing purposes while processors act under applicable instructions; exact legal duties depend on jurisdiction and contract.
The lifecycle runs through collection/creation, use, sharing, storage, retention and disposal. Minimize collection, restrict purpose and access, discover misplaced sensitive data and track copies. Data residency describes where data is stored; sovereignty/jurisdiction concerns which laws may apply. Encryption does not automatically resolve every cross-border obligation.
Choose disposal by medium and sensitivity: clear, purge or physically destroy using an approved sanitization method. A quick format or ordinary file deletion may leave recoverable data. Track disposal and verify sanitization; retain evidence when required. Legal holds can override routine deletion.
RPO measures tolerable lost data in time; RTO measures target restoration time. A business impact analysis prioritizes services and dependencies. High availability handles component failures; backups recover prior data; disaster recovery restores technology; business continuity sustains critical business operations.
Full backups simplify restoration but copy more data. Incremental backups copy changes since the preceding backup and may require a chain; differential backups copy changes since the full backup. Offline/isolated or suitably immutable copies resist attacks on live systems. Replication can also replicate corruption and deletion.
Hot, warm and cold recovery sites trade readiness for cost. Test restoration, application consistency, key availability, access, DNS and dependent services. Redundant power, UPS/generators, geographic diversity and people/process continuity address different failure modes.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Recover yesterday’s deleted records | A tested point-in-time/backup capability, not only replication. |
| Minimal data loss after disaster | A replication/backup frequency consistent with the RPO. |
| Retire sensitive storage | Approved sanitization with verification and records. |
Traps
- Replication is not a substitute for independent recovery history.
- A backup without usable decryption keys may be worthless.