220-1101 exam dumps

220-1101 practice question 330 of 471

A+ Core 1. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1101 Question 330

Single answerAudit logs

A technician is asked to investigate why a shared office workstation became unavailable for several minutes during business hours. The user reports that the system suddenly restarted and displayed a message about installing updates. The technician needs to confirm exactly when the restart occurred and what triggered it, using built-in Windows tools. Which log should the technician review first?

  1. A

    Security log in Event Viewer

  2. B

    Setup log in Event Viewer

  3. C

    System log in Event Viewer

  4. D

    Application log in Event Viewer

Show answer and explanation

Correct answer: C

Explanation

In a real support scenario, the best first step is to review the System log in Event Viewer because it contains operating system-level events such as restart, shutdown, power, service, and driver entries. On Windows systems, technicians commonly use Event Viewer to correlate restart behavior with entries from sources such as User32, EventLog, WindowsUpdateClient, or Kernel-Power. The Security log is focused on audited security activity, the Application log is for app-generated events, and the Setup log is more limited to installation and setup processes. Microsoft documentation and standard help desk troubleshooting practices consistently identify the System log as the primary source for diagnosing unexpected restarts and system-initiated update reboots.

  • A. Incorrect.

    The Security log records audited security-related events such as logon attempts, account access, and privilege use. Although useful for investigating unauthorized access, it is not the primary place to confirm a restart caused by updates or other operating system events.

  • B. Incorrect.

    The Setup log is mainly used for events related to Windows installation and role or feature setup. A technician might think updates belong here because they involve installation activity, but unexpected restarts and shutdown-related operating system events are typically documented first in the System log.

  • C. Correct.

    The System log is correct because it records operating system events generated by Windows system components, including shutdowns, restarts, driver issues, and update-related restart events. For a workstation that restarted unexpectedly or due to updates, this is the best first place to verify timing and cause.

  • D. Incorrect.

    The Application log contains events generated by user applications and some software services. It may show errors from a specific program, but it is not the primary log for confirming that Windows itself initiated a restart for updates.

Timed practice exam

Take a 220-1101 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam