All certifications / A+ Core 2 / Lessons
A+ Core 2 220-1202 lessons
Study A+ Core 2 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the A+ Core 2 study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Operating systems
- OS types and purposes: Windows, macOS, Linux, ChromeOS, iOS/iPadOS, Android; vendor life cycles and end-of-life
- File systems: NTFS, ReFS, FAT32, exFAT, ext4, XFS, APFS and their limits
- Installations and upgrades: boot methods (USB, PXE, ISO), clean vs in-place vs image deployment vs repair install, GPT vs MBR, third-party drivers
- Windows 10/11 editions (Home, Pro, Enterprise, Education) and which features each has: BitLocker, domain join, Group Policy, Remote Desktop host
- Windows tools: Task Manager, MMC snap-ins (Event Viewer, Disk Management, Task Scheduler, Device Manager, Certificate Manager, Local Users and Groups, Performance Monitor, Group Policy Editor), msinfo32, Resource Monitor, System Configuration, Registry Editor, Disk Cleanup
- Command-line tools: cd, dir, md, rmdir, robocopy, xcopy, diskpart, format, chkdsk, sfc, DISM, gpupdate, gpresult, net use, net user, whoami, winver, shutdown, ipconfig, ping, tracert, pathping, nslookup, netstat, hostname
- Settings and Control Panel: Accounts, Privacy, Update and Security, Apps, Power Options (sleep, hibernate, fast startup), Display, Devices
- Windows networking: workgroup vs domain, mapped drives and shares, firewall exceptions, static vs DHCP addressing, VPN and proxy settings, public vs private network profiles, metered connections
- MacOS: installing and removing apps (.dmg, .pkg, .app, App Store), System Settings, Time Machine, FileVault, Keychain, Spotlight, Mission Control, Terminal, Disk Utility, Force Quit
- Linux: file and permission commands (ls, cp, mv, rm, chmod, chown, sudo, su), package managers (apt, dnf), ip, df, top, ps, grep, find, man, key files (/etc/passwd, /etc/shadow, /etc/hosts, /etc/fstab, /etc/resolv.conf)
- Installing applications: 32- vs 64-bit, RAM/CPU/GPU/storage requirements, distribution methods (ISO, download, image) and business impact
- Cloud productivity tools: email, synced storage, collaboration suites, account setup and licensing
Domain 2: Security
- Physical security: access control vestibules, badge readers, video surveillance, alarm systems, locks, guards, bollards, fences
- Logical security: least privilege, zero trust, MFA methods (authenticator apps, SMS, hardware tokens, email), SSO, MDM, DLP, IAM, directory services, access control lists
- Windows security: Microsoft Defender Antivirus and Firewall, users and groups, NTFS vs share permissions, inheritance, UAC, BitLocker and BitLocker To Go, EFS, Windows Hello, run as administrator
- Wireless security: WPA2 vs WPA3, AES vs TKIP, RADIUS, TACACS+, Kerberos, multifactor
- Malware: virus, trojan, rootkit, ransomware, keylogger, spyware, adware, cryptominer, boot sector virus, stalkerware, fileless malware; tools such as anti-malware, recovery console, EDR/MDR/XDR, email security gateways
- Social engineering and threats: phishing, vishing, smishing, QR code phishing, whaling, impersonation, tailgating, shoulder surfing, dumpster diving, evil twin, DoS/DDoS, zero-day, on-path, brute force, insider threat, SQL injection, XSS, BEC, supply chain
- The seven-step malware removal procedure, in order
- Workstation hardening: data-at-rest encryption, password policy, end-user best practices (screensaver locks, logging off), account management, disable AutoRun/AutoPlay, disable guest account
- Mobile device security: screen locks, remote wipe, locator apps, OS updates, device encryption, remote backup, MDM, BYOD vs corporate-owned
- Data destruction: shredding, drilling, degaussing, incineration; erasing/wiping vs low-level vs standard format; certificates of destruction
- SOHO router hardening: default passwords, firmware updates, disabling WPS and UPnP, content filtering, port forwarding, DHCP reservations, guest networks
- Browser security: trusted sources and hash checks, extensions, password managers, certificates, pop-up blockers, clearing cache, private browsing, profile sync
Domain 3: Software troubleshooting
- Windows symptoms: blue screen (BSOD), degraded performance, boot problems, frequent shutdowns, services not starting, application crashes, low memory warnings, USB controller resource warnings, system instability, no OS found, slow profile load, time drift
- Windows fixes: reboot, restart services, uninstall/reinstall/update apps, add resources, verify requirements, sfc and DISM, repair Windows, System Restore, reimage, roll back updates, rebuild the user profile
- Using Event Viewer, Reliability Monitor, Task Manager and Safe Mode / Windows Recovery Environment to find root causes
- Mobile OS and app issues: app fails to launch, close or update; slow response; poor battery life; random reboots; Bluetooth, Wi-Fi and NFC connectivity; screen won't autorotate
- Mobile security issues: unofficial app stores, jailbreaking and rooting, sideloaded APKs, high network traffic, data-limit alerts, sluggish response, fake security warnings, unexpected app behavior, leaked personal files
- PC security issues: unable to reach the network, fake antivirus alerts, altered or missing system files, unwanted OS notifications, failed OS updates
- Browser security issues: random pop-ups, certificate warnings, redirection, degraded browser performance
- Checking and repairing startup items, scheduled tasks, browser extensions and proxy settings after an infection
Domain 4: Operational procedures
- Ticketing systems: user and device information, descriptions, categories, severity, escalation levels, clear progress notes and resolutions
- Asset management: inventory lists, CMDB, asset tags and IDs, procurement life cycle, warranty and licensing, assigned users
- Documentation types: acceptable use policy, incident reports, SOPs, onboarding and offboarding checklists, SLAs, knowledge base articles
- Change management: request forms, purpose and scope, risk analysis, change advisory board approval, sandbox testing, rollback and backup plans, end-user acceptance
- Backup and recovery: full, incremental, differential and synthetic backups; testing restores; on-site vs off-site; 3-2-1 rule; grandfather-father-son rotation
- Safety: ESD straps and mats, grounding, power handling, lifting technique, electrical fire safety, PPE
- Environment: safety data sheets, battery and toner disposal, temperature and humidity, ventilation, UPS and surge suppressors
- Prohibited content and privacy: incident response and chain of custody, licensing (EULA, DRM, open source vs commercial, personal vs corporate), PII, PCI DSS, GDPR, PHI, data retention
- Professionalism: punctuality, active listening, avoiding jargon, handling difficult customers, confidentiality, setting expectations and following up
- Scripting basics: .bat, .ps1, .vbs, .sh, .js, .py; use cases (automation, restarts, drive mapping, installs, backups, updates) and risks
- Remote access: RDP, VPN, VNC, SSH, RMM, SPICE, WinRM, screen-sharing and file-transfer tools, and their security considerations
- Artificial intelligence basics: app integration, appropriate-use policy and plagiarism, bias, hallucinations and accuracy, public vs private models and data privacy