220-1102 exam dumps

220-1102 practice question 84 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 84

Single answerEvent Viewer (eventvwr.msc)

A user reports that their Windows 10 laptop unexpectedly restarts several times a day with no error message. You need to use Event Viewer to quickly identify whether the restarts are being caused by system crashes or sudden power loss. Which action should you take first?

  1. A

    Open Event Viewer and review the System log for Critical and Error events around the restart times, especially entries such as Kernel-Power and BugCheck

  2. B

    Open Event Viewer and clear the Application log so new restart events are easier to identify

  3. C

    Open Event Viewer and enable analytic and debug logs for all categories before reviewing the events

  4. D

    Open Event Viewer and review the Security log first to determine whether a user forced the restart

Show answer and explanation

Correct answer: A

Explanation

The best first step is to examine the System log in Event Viewer (eventvwr.msc), because Windows records shutdown, restart, hardware, driver, and kernel-related events there. In real-world troubleshooting, technicians typically filter the System log by Critical and Error levels and compare event timestamps with the user's report. Important examples include Kernel-Power events indicating the system did not shut down cleanly and BugCheck events indicating a stop error occurred. Microsoft documentation for Event Viewer and Windows event logs supports using the System log for operating system and hardware-related troubleshooting. Clearing logs prematurely is poor practice because it removes evidence, and enabling analytic/debug logs is unnecessary for initial diagnosis.

  • A. Correct.

    Correct. In Event Viewer, unexpected shutdowns, power-loss events, and crash-related entries are most commonly found in Windows Logs > System. Filtering or reviewing Critical and Error events around the reported time is the fastest practical troubleshooting step. Entries such as Kernel-Power (commonly Event ID 41) can indicate the system restarted without a clean shutdown, while BugCheck events can indicate a blue screen or system crash. This is the most direct way to determine whether the restart was likely caused by a crash or abrupt power interruption.

  • B. Incorrect.

    Incorrect. Clearing logs is not an appropriate first step because it destroys useful historical evidence that may be needed to correlate the restart times and identify patterns. Best practice is to review or filter existing events first, and export logs if needed before making changes. A technician who chooses this may be thinking about reducing clutter, but that would hinder troubleshooting.

  • C. Incorrect.

    Incorrect. Analytic and debug logs are not typically necessary for initial A+ level troubleshooting of unexpected restarts. They are more advanced, can generate large amounts of data, and are not the quickest first step for determining whether a restart was caused by a crash or power issue. The System log usually contains the relevant information already.

  • D. Incorrect.

    Incorrect. The Security log focuses on audited security-related events such as logons, privilege use, and policy changes. While some shutdown-related activity can appear if auditing is configured, it is not the primary or most efficient place to begin when investigating unexpected restarts. A technician might choose this if they suspect intentional user action, but the question asks for the best first action to distinguish crashes from power loss.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam