StudyToCert

All certifications / Server+ / Cheat sheet

Server+ SK0-005 cheat sheet

Every exam tip and key term from the free Server+ lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Server hardware installation and management (18%)

Exam tips

Key terms

Rack unit (U)
The standard vertical measure for rack equipment: 1.75 inches (44.45 mm).
Hot aisle/cold aisle
A layout where rack fronts face a shared cool-air aisle and backs face a shared exhaust aisle, keeping intake and exhaust air separate.
Blanking panel
A plate that covers an empty rack space so hot exhaust air cannot loop back to the equipment intakes.
Cable management arm (CMA)
A hinged arm on the back of a sliding server that carries its cables so the server can be extended without disconnecting them.
Tower server
A free-standing server in an upright case, suited to small sites without a rack.
Rack mount server
A server built to bolt into a 19-inch rack, sized in rack units (1U, 2U, 4U).
Blade enclosure
A rack-mounted chassis that supplies shared power, cooling, networking and management to the blade servers inserted into it.
Blade server
A thin server module containing CPU and memory that depends on its enclosure for power, cooling and connectivity.
Redundant power supply
A second PSU that can carry the full load if the first fails, usually hot-swappable.
PDU (power distribution unit)
A rack-mounted outlet strip; metered models report load and switched models allow remote outlet control.
UPS (uninterruptible power supply)
A battery-backed device that keeps equipment powered through short outages and conditions incoming power.
Automatic transfer switch (ATS)
A device that moves the load from utility power to a generator when utility power fails.
Cat6a
Augmented Category 6 twisted-pair cable that supports 10 Gbps Ethernet up to 100 meters.
Single-mode fiber
Fiber with a very small core that carries one light path over long distances, used for building-to-building and long-haul links.
Multimode fiber
Fiber with a larger core that carries multiple light paths over shorter distances, common inside data centers.
DAC (direct attach copper)
A twinax cable with transceiver-style ends attached, used for short, low-cost high-speed links within or between adjacent racks.
IOPS
Input/output operations per second, a measure of how many reads and writes storage can handle.
SAS (Serial Attached SCSI)
An enterprise drive interface with dual-port support and robust error handling; SAS controllers can also run SATA drives.
NVMe
A storage protocol that connects flash drives directly to the PCIe bus for very low latency and high throughput.
Hot-swap
Replacing a component while the system runs, with no shutdown or special OS action required.
Parity
Calculated data stored in RAID 5 or 6 that lets the array reconstruct the contents of a failed drive.
Write penalty
The number of physical I/O operations one logical write requires: 1 for RAID 0, 2 for RAID 1 and 10, 4 for RAID 5, 6 for RAID 6.
Hot spare
A standby drive that the controller automatically uses to rebuild an array after a member fails.
JBOD
Just a bunch of disks: drives presented individually or concatenated, with no redundancy.
NAS
Network-attached storage: a device that shares files over the network with protocols such as SMB and NFS.
SAN
Storage area network: a dedicated network that presents block-level storage (LUNs) to servers.
iSCSI
A protocol that carries SCSI block commands over TCP/IP, using initiators on servers and targets on storage.
LUN
Logical unit number: a block storage volume presented by a SAN to a server.
BMC (baseboard management controller)
An independent controller on the motherboard that provides monitoring and remote control even when the OS is down.
IPMI
Intelligent Platform Management Interface, a standard protocol for communicating with BMCs.
IP KVM
A keyboard-video-mouse switch reachable over the network, giving remote console access including BIOS screens.
Crash cart
A mobile cart with monitor, keyboard and mouse used to connect locally to a server.
UEFI
Unified Extensible Firmware Interface, the modern firmware replacing BIOS, with GPT support and Secure Boot.
Secure Boot
A UEFI feature that allows only digitally signed, trusted bootloaders and drivers to run at startup.
TPM (Trusted Platform Module)
A hardware security chip that stores cryptographic keys and records measurements of the boot process.
Boot order
The sequence of devices the firmware tries when looking for an operating system to start.
ECC memory
RAM that uses extra bits to detect and correct single-bit errors, preventing silent corruption.
Registered memory (RDIMM)
Memory with a register that buffers signals, allowing more modules and larger capacity per server.
Core
An independent processing unit within a CPU; one socket can contain many cores.
Hot-swappable
Able to be replaced while the system stays powered on and running.

Domain 2: Server administration (30%)

Exam tips

Key terms

HCL (hardware compatibility list)
A vendor's list of hardware tested and supported with a given OS or hypervisor.
Server Core
A Windows Server installation option without the desktop GUI, managed from the command line or remotely.
ReFS
Resilient File System, a Windows file system focused on integrity and large volumes, often used for virtualization and backup storage.
VMFS
VMware's clustered file system that lets several ESXi hosts share a datastore.
PXE
Preboot Execution Environment: booting a computer over the network using DHCP and TFTP to load an installer or image.
Answer file
A file that supplies installer responses automatically, such as unattend.xml or Kickstart.
Sysprep
A Windows tool that generalizes an installation, removing unique identifiers before it is captured as an image.
P2V
Physical-to-virtual conversion of an existing physical server into a virtual machine.
DHCP reservation
A DHCP setting that always assigns the same IP address to a specific device's MAC address.
NIC teaming/bonding
Combining multiple network adapters into one logical interface for redundancy and possibly more bandwidth.
802.1Q
The standard for VLAN tagging, which marks Ethernet frames with a VLAN ID so one link can carry multiple VLANs.
NTP
Network Time Protocol, used to keep system clocks synchronized; it uses UDP port 123.
Server role
The primary function a server provides to clients, such as web, database or file services.
Domain controller
A server running directory services that stores accounts and authenticates users and computers in a domain.
Application server
A server that runs business logic, often sitting between web front ends and databases.
Sizing
Choosing CPU, memory, storage and network capacity to meet a workload's needs plus growth and headroom.
Active-passive cluster
A cluster in which one node serves while another waits to take over on failure.
Heartbeat
A periodic signal nodes exchange to confirm each other is alive.
Quorum
The majority vote a cluster requires to keep running, preventing split brain.
Least connections
A load-balancing method that sends new requests to the server with the fewest active connections.
Single point of failure (SPOF)
Any component whose failure alone stops the whole system.
MPIO (multipath I/O)
Software that uses multiple physical paths to the same storage for failover and load balancing, presenting them as one disk.
Fault tolerance
The ability to keep operating with no interruption when a component fails.
High availability
Design that minimizes downtime, allowing a short interruption while failover occurs.
Type 1 hypervisor
A bare-metal hypervisor installed directly on hardware, used in production.
Overcommitment
Allocating more virtual CPU or memory to VMs than the host physically has.
Snapshot
A point-in-time capture of a VM's state used for short-term rollback, not a backup.
Live migration
Moving a running VM from one host to another without shutting it down.
IaaS
Infrastructure as a Service: rented VMs, storage and networks where the customer manages the OS and above.
PaaS
Platform as a Service: a managed runtime where the customer deploys code without managing servers.
SaaS
Software as a Service: a complete application run by the provider and used by the customer.
Hybrid cloud
A combination of on-premises or private resources and public cloud services that work together.
Variable
A named storage location for a value that a script can read and change.
Loop
A structure that repeats commands, such as for (per item) or while (until a condition changes).
Comparator
An operator that compares values, such as -eq or -gt in shells and == or > in Python.
cron
The Linux scheduler that runs commands at set times defined in a crontab.
CMDB
Configuration management database: a record of IT assets, their configuration and relationships.
Baseline
A documented standard configuration or normal performance level used for comparison.
Change management
A controlled process to request, approve, schedule, implement and document changes with rollback plans.
SLA
Service level agreement: a formal commitment on service performance such as uptime or response time.
Per-core licensing
A model that charges for each physical processor core, often with per-processor or per-server minimums.
CAL (client access license)
A license that permits a user or device to access server software.
Subscription license
A recurring-fee license that includes updates and ends when payments stop.
Site license
A license allowing unlimited use within a defined location or organization for a set fee.

Domain 3: Security and disaster recovery (24%)

Exam tips

Key terms

Encryption at rest
Encrypting stored data so it is unreadable without the key if media is stolen or copied.
Encryption in transit
Encrypting data as it travels across networks, for example with TLS or SSH.
Data retention policy
Rules specifying how long data is kept and when it must be destroyed.
Data sovereignty
The principle that data is subject to the laws of the country where it is physically stored.
Access control vestibule (mantrap)
A two-door entry space where only one door can open at a time, preventing tailgating.
Tailgating
Following an authorized person through a secure door without authenticating.
Biometrics
Authentication based on physical characteristics such as fingerprints or iris patterns.
Clean agent suppression
Fire suppression using gases that extinguish fire without water damage or residue on equipment.
Least privilege
Granting only the minimum permissions needed to perform a task.
RBAC (role-based access control)
Assigning permissions to roles and placing users in roles rather than granting rights individually.
MFA
Multifactor authentication: requiring two or more different types of authentication factors.
Service account
A non-human account used by an application or service to run and access resources.
DLP (data loss prevention)
Tools and policies that detect and block sensitive data from leaving authorized locations.
Ransomware
Malware that encrypts data and demands payment, often also stealing data for extortion.
Insider threat
Risk posed by people with legitimate access who misuse it maliciously or carelessly.
Network segmentation
Dividing a network into isolated zones to limit access and the spread of attacks.
Attack surface
All the points where an attacker could interact with or enter a system.
Host-based firewall
A firewall running on the server itself that filters its inbound and outbound traffic.
EDR
Endpoint detection and response: security software that monitors host behavior, detects threats and supports response.
Security baseline
A documented set of hardening settings that systems must meet.
Wiping
Overwriting all sectors of storage media so previous data cannot be recovered, allowing reuse.
Degaussing
Erasing magnetic media with a strong magnetic field, rendering hard drives unusable; ineffective on SSDs.
Crypto-erase
Sanitizing a self-encrypting drive by destroying its encryption key.
Certificate of destruction
A document confirming which media were destroyed, how, when and by whom.
Incremental backup
Copies data changed since the last backup of any type; restores need the full plus every incremental since.
Differential backup
Copies data changed since the last full backup; restores need the full plus the latest differential.
Synthetic full
A full backup assembled on the backup server from a prior full and later incrementals.
Grandfather-father-son (GFS)
A rotation scheme keeping daily, weekly and monthly backup sets for different retention periods.
Retention period
How long a backup copy is kept before it is expired and deleted.
Off-site backup
A backup copy stored at a different location to survive site-wide disasters.
Test restore
Restoring data from backup to verify the backup is complete and usable.
Application-aware backup
A backup that coordinates with an application so its data is captured in a consistent state.
RPO
Recovery point objective: the maximum acceptable amount of data loss, measured in time.
RTO
Recovery time objective: the maximum acceptable time to restore a service.
Hot site
A fully equipped recovery site with current data, ready to take over quickly.
Synchronous replication
Replication that confirms a write only after both sites have it, giving near-zero data loss at the cost of latency.
BIA (business impact analysis)
An analysis of business processes, their dependencies and the impact of their disruption over time.
MTBF
Mean time between failures: the average operating time between failures of a repairable item.
MTTR
Mean time to repair: the average time needed to restore a failed item or service.
Communication plan
The documented process and contacts for sharing information during an incident.

Domain 4: Troubleshooting (28%)

Exam tips

Key terms

Theory of probable cause
The best current explanation for a problem, formed after gathering information and tested before acting.
Escalation
Passing a problem to someone with more expertise or authority when you cannot resolve it.
Preventive measures
Actions taken after a fix to stop the same problem from happening again.
Scope
How widespread a problem is, such as one user, one server or an entire site.
POST
Power-on self-test: firmware checks run at startup that report hardware faults.
Beep code
A pattern of beeps at startup indicating a hardware error; meanings vary by vendor.
Predictive failure
An alert that a component, such as a drive, shows signs it is likely to fail soon.
UID LED
A unit identification light used to locate a specific server or component in a rack.
Degraded array
A RAID array that has lost a member but still serves data without redundancy.
Write-back cache
Controller caching that confirms writes before they reach disk; requires battery or flash protection.
Write-through
Caching mode that confirms writes only after they reach disk, safer but slower.
fstab
The Linux file that lists which file systems to mount at boot and where.
chkdsk
Windows tool that checks and repairs file system errors; /f fixes errors and /r also scans for bad sectors.
fsck
Linux file system consistency checker, run on unmounted file systems.
smartctl
A command-line tool that reads SMART health data from drives.
parted
A Linux partitioning tool that supports GPT disks and resizing.
Memory leak
A defect where a program keeps allocating memory without releasing it, gradually exhausting RAM.
Runaway process
A process consuming excessive CPU or resources, often stuck in a loop.
Boot loop
A condition where a system restarts repeatedly without completing startup.
Service dependency
Another service that must be running before a given service can start.
Event Viewer
The Windows tool for reading Application, System, Security and other event logs.
journalctl
The command for querying the systemd journal on Linux, filterable by unit, boot, priority and time.
Performance Monitor
The Windows tool that displays and logs performance counters over time.
Safe mode
A Windows startup mode that loads only essential drivers and services for troubleshooting.
APIPA
Automatic Private IP Addressing: a 169.254.x.x address a Windows host assigns itself when DHCP fails.
Default gateway
The router address a host uses to reach networks outside its own subnet.
Duplex mismatch
A link where one side runs full duplex and the other half duplex, causing errors and poor performance.
Hosts file
A local file that maps names to IP addresses and is checked before DNS on most systems.
traceroute/tracert
A tool that lists each router hop to a destination and the delay to each.
nslookup/dig
Tools that query DNS servers directly to check name resolution.
ss/netstat
Tools that list network connections and listening ports, optionally with the owning process.
Test-NetConnection
A PowerShell cmdlet that tests connectivity, including whether a TCP port is reachable.
Effective permissions
The actual access a user has after combining all group permissions, deny entries and share and NTFS permissions.
Certificate chain
The server certificate plus the intermediate certificates linking it to a trusted root.
False positive
A security tool flagging legitimate activity or files as malicious.
Indicator of compromise
Evidence, such as unusual logons or unknown services, suggesting a system or account has been breached.
Root cause
The underlying reason a problem occurred, which, when fixed, prevents recurrence.
Performance counter
A measured value, such as disk queue length or available memory, tracked by the OS or monitoring tools.
Bottleneck
The resource that limits overall performance because it is saturated.
SIEM
Security information and event management: a system that collects and correlates logs from many sources.
Study Server+ for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Server+ study plan