All certifications / Server+ / Cheat sheet
Server+ SK0-005 cheat sheet
Domain 1: Server hardware installation and management (18%)
Exam tips
- If a question asks where to put the UPS or the heaviest device, the answer is the bottom of the rack. If it asks how to stop hot air recirculating through empty rack spaces, the answer is blanking panels.
- Blades win on density and cabling but depend on a shared enclosure and one vendor. If a question stresses fewer cables, shared power and cooling and centralized management, think blade.
- Redundant PSUs plugged into the same PDU or circuit are not really redundant. Exam answers favor A and B feeds on separate circuits, and UPS runtime is determined by load, not just the UPS size.
- Distance decides most cabling questions: DAC for a few meters, multimode for runs within the data center, single-mode for kilometers. Cat6a is the copper answer for 10 Gbps at 100 meters.
- Faster RPM means more IOPS but less capacity and more cost per GB. SAS controllers accept SATA drives but not the other way round, and hot-swap requires no OS preparation while hot-plug may.
- Memorize the formulas: RAID 5 = N-1, RAID 6 = N-2, RAID 1 and 10 = N/2. Write penalties are 2, 4 and 6 for mirroring, RAID 5 and RAID 6. RAID never replaces backups.
- File-level sharing (SMB, NFS) means NAS; block-level (LUNs over FC or iSCSI) means SAN. iSCSI rides on IP; FCoE rides directly on Ethernet without IP. Drives are sold in base-10 but reported in base-2.
- If the OS is down or the server is powered off and you must reach it remotely, the answer is out-of-band management (BMC, iLO, iDRAC, IPMI). Securing it means a separate management network and changed default credentials.
- Secure Boot verifies signatures of boot code; the TPM stores keys and measures boot integrity. Exam answers on updates favor testing first, following the vendor's order and compatibility matrix, and having a rollback plan.
- ECC corrects errors; registered buffers signals for capacity. Do not mix RDIMMs and UDIMMs. Drives, PSUs and fans are the usual hot-swap parts; CPUs and RAM normally require downtime.
Key terms
- Rack unit (U)
- The standard vertical measure for rack equipment: 1.75 inches (44.45 mm).
- Hot aisle/cold aisle
- A layout where rack fronts face a shared cool-air aisle and backs face a shared exhaust aisle, keeping intake and exhaust air separate.
- Blanking panel
- A plate that covers an empty rack space so hot exhaust air cannot loop back to the equipment intakes.
- Cable management arm (CMA)
- A hinged arm on the back of a sliding server that carries its cables so the server can be extended without disconnecting them.
- Tower server
- A free-standing server in an upright case, suited to small sites without a rack.
- Rack mount server
- A server built to bolt into a 19-inch rack, sized in rack units (1U, 2U, 4U).
- Blade enclosure
- A rack-mounted chassis that supplies shared power, cooling, networking and management to the blade servers inserted into it.
- Blade server
- A thin server module containing CPU and memory that depends on its enclosure for power, cooling and connectivity.
- Redundant power supply
- A second PSU that can carry the full load if the first fails, usually hot-swappable.
- PDU (power distribution unit)
- A rack-mounted outlet strip; metered models report load and switched models allow remote outlet control.
- UPS (uninterruptible power supply)
- A battery-backed device that keeps equipment powered through short outages and conditions incoming power.
- Automatic transfer switch (ATS)
- A device that moves the load from utility power to a generator when utility power fails.
- Cat6a
- Augmented Category 6 twisted-pair cable that supports 10 Gbps Ethernet up to 100 meters.
- Single-mode fiber
- Fiber with a very small core that carries one light path over long distances, used for building-to-building and long-haul links.
- Multimode fiber
- Fiber with a larger core that carries multiple light paths over shorter distances, common inside data centers.
- DAC (direct attach copper)
- A twinax cable with transceiver-style ends attached, used for short, low-cost high-speed links within or between adjacent racks.
- IOPS
- Input/output operations per second, a measure of how many reads and writes storage can handle.
- SAS (Serial Attached SCSI)
- An enterprise drive interface with dual-port support and robust error handling; SAS controllers can also run SATA drives.
- NVMe
- A storage protocol that connects flash drives directly to the PCIe bus for very low latency and high throughput.
- Hot-swap
- Replacing a component while the system runs, with no shutdown or special OS action required.
- Parity
- Calculated data stored in RAID 5 or 6 that lets the array reconstruct the contents of a failed drive.
- Write penalty
- The number of physical I/O operations one logical write requires: 1 for RAID 0, 2 for RAID 1 and 10, 4 for RAID 5, 6 for RAID 6.
- Hot spare
- A standby drive that the controller automatically uses to rebuild an array after a member fails.
- JBOD
- Just a bunch of disks: drives presented individually or concatenated, with no redundancy.
- NAS
- Network-attached storage: a device that shares files over the network with protocols such as SMB and NFS.
- SAN
- Storage area network: a dedicated network that presents block-level storage (LUNs) to servers.
- iSCSI
- A protocol that carries SCSI block commands over TCP/IP, using initiators on servers and targets on storage.
- LUN
- Logical unit number: a block storage volume presented by a SAN to a server.
- BMC (baseboard management controller)
- An independent controller on the motherboard that provides monitoring and remote control even when the OS is down.
- IPMI
- Intelligent Platform Management Interface, a standard protocol for communicating with BMCs.
- IP KVM
- A keyboard-video-mouse switch reachable over the network, giving remote console access including BIOS screens.
- Crash cart
- A mobile cart with monitor, keyboard and mouse used to connect locally to a server.
- UEFI
- Unified Extensible Firmware Interface, the modern firmware replacing BIOS, with GPT support and Secure Boot.
- Secure Boot
- A UEFI feature that allows only digitally signed, trusted bootloaders and drivers to run at startup.
- TPM (Trusted Platform Module)
- A hardware security chip that stores cryptographic keys and records measurements of the boot process.
- Boot order
- The sequence of devices the firmware tries when looking for an operating system to start.
- ECC memory
- RAM that uses extra bits to detect and correct single-bit errors, preventing silent corruption.
- Registered memory (RDIMM)
- Memory with a register that buffers signals, allowing more modules and larger capacity per server.
- Core
- An independent processing unit within a CPU; one socket can contain many cores.
- Hot-swappable
- Able to be replaced while the system stays powered on and running.
Domain 2: Server administration (30%)
Exam tips
- Core or headless installs are the answer when a question stresses smaller attack surface and fewer updates. Know which file system fits which platform: NTFS/ReFS for Windows, ext4/XFS for Linux, VMFS for VMware datastores.
- PXE depends on DHCP and TFTP plus network boot in the boot order. Always generalize a Windows image (Sysprep) before cloning so machines do not share identifiers.
- Servers get static addresses or reservations, not dynamic leases. Time drift breaks Kerberos authentication. LACP teaming needs switch configuration; simple failover teaming does not.
- When a question asks which resource matters most: databases and virtualization hosts want memory and fast storage, file servers want capacity and network throughput, and DNS/DHCP want redundancy more than power.
- Quorum and witnesses exist to prevent split brain. Round robin assumes equal servers and requests; least connections suits uneven or long sessions. Active-active nodes need spare capacity to absorb a failed partner's load.
- Fault tolerant means zero interruption; highly available means a brief interruption during failover. MPIO is the answer for redundant storage paths, NIC teaming for redundant network links.
- Type 1 runs on bare metal and is used in data centers; Type 2 runs on a host OS. Snapshots are for short-term rollback and hurt performance if kept; they are never a substitute for backups.
- Ask who patches the OS: you do in IaaS, the provider does in PaaS and SaaS. The customer is always responsible for data and user access regardless of model.
- Identify the language from clues: $ variables with -eq and cmdlets like Get-Item mean PowerShell; shebang and [ ] tests mean Bash; %var% means batch; indentation with == means Python.
- Changes need a documented request, approval, a maintenance window and a rollback plan. A baseline is what you compare against to tell whether current behavior is abnormal.
- User CALs fit people with many devices; device CALs fit devices shared by many people. More cores can mean higher costs under per-core licensing, even if the hardware is cheap.
Key terms
- HCL (hardware compatibility list)
- A vendor's list of hardware tested and supported with a given OS or hypervisor.
- Server Core
- A Windows Server installation option without the desktop GUI, managed from the command line or remotely.
- ReFS
- Resilient File System, a Windows file system focused on integrity and large volumes, often used for virtualization and backup storage.
- VMFS
- VMware's clustered file system that lets several ESXi hosts share a datastore.
- PXE
- Preboot Execution Environment: booting a computer over the network using DHCP and TFTP to load an installer or image.
- Answer file
- A file that supplies installer responses automatically, such as unattend.xml or Kickstart.
- Sysprep
- A Windows tool that generalizes an installation, removing unique identifiers before it is captured as an image.
- P2V
- Physical-to-virtual conversion of an existing physical server into a virtual machine.
- DHCP reservation
- A DHCP setting that always assigns the same IP address to a specific device's MAC address.
- NIC teaming/bonding
- Combining multiple network adapters into one logical interface for redundancy and possibly more bandwidth.
- 802.1Q
- The standard for VLAN tagging, which marks Ethernet frames with a VLAN ID so one link can carry multiple VLANs.
- NTP
- Network Time Protocol, used to keep system clocks synchronized; it uses UDP port 123.
- Server role
- The primary function a server provides to clients, such as web, database or file services.
- Domain controller
- A server running directory services that stores accounts and authenticates users and computers in a domain.
- Application server
- A server that runs business logic, often sitting between web front ends and databases.
- Sizing
- Choosing CPU, memory, storage and network capacity to meet a workload's needs plus growth and headroom.
- Active-passive cluster
- A cluster in which one node serves while another waits to take over on failure.
- Heartbeat
- A periodic signal nodes exchange to confirm each other is alive.
- Quorum
- The majority vote a cluster requires to keep running, preventing split brain.
- Least connections
- A load-balancing method that sends new requests to the server with the fewest active connections.
- Single point of failure (SPOF)
- Any component whose failure alone stops the whole system.
- MPIO (multipath I/O)
- Software that uses multiple physical paths to the same storage for failover and load balancing, presenting them as one disk.
- Fault tolerance
- The ability to keep operating with no interruption when a component fails.
- High availability
- Design that minimizes downtime, allowing a short interruption while failover occurs.
- Type 1 hypervisor
- A bare-metal hypervisor installed directly on hardware, used in production.
- Overcommitment
- Allocating more virtual CPU or memory to VMs than the host physically has.
- Snapshot
- A point-in-time capture of a VM's state used for short-term rollback, not a backup.
- Live migration
- Moving a running VM from one host to another without shutting it down.
- IaaS
- Infrastructure as a Service: rented VMs, storage and networks where the customer manages the OS and above.
- PaaS
- Platform as a Service: a managed runtime where the customer deploys code without managing servers.
- SaaS
- Software as a Service: a complete application run by the provider and used by the customer.
- Hybrid cloud
- A combination of on-premises or private resources and public cloud services that work together.
- Variable
- A named storage location for a value that a script can read and change.
- Loop
- A structure that repeats commands, such as for (per item) or while (until a condition changes).
- Comparator
- An operator that compares values, such as -eq or -gt in shells and == or > in Python.
- cron
- The Linux scheduler that runs commands at set times defined in a crontab.
- CMDB
- Configuration management database: a record of IT assets, their configuration and relationships.
- Baseline
- A documented standard configuration or normal performance level used for comparison.
- Change management
- A controlled process to request, approve, schedule, implement and document changes with rollback plans.
- SLA
- Service level agreement: a formal commitment on service performance such as uptime or response time.
- Per-core licensing
- A model that charges for each physical processor core, often with per-processor or per-server minimums.
- CAL (client access license)
- A license that permits a user or device to access server software.
- Subscription license
- A recurring-fee license that includes updates and ends when payments stop.
- Site license
- A license allowing unlimited use within a defined location or organization for a set fee.
Domain 3: Security and disaster recovery (24%)
Exam tips
- At rest means stored (BitLocker, LUKS, self-encrypting drives); in transit means moving (TLS, SSH, IPsec). A firmware setup password stops boot-order changes; a GRUB password stops boot-entry edits.
- Mantraps/vestibules stop tailgating. Pre-action and clean agent systems are preferred where electronics must be protected; standard wet-pipe sprinklers risk water damage.
- MFA must combine different factor types; a password plus a PIN is still single-factor. Grant permissions to groups, not individuals, and give service accounts their own least-privilege identities.
- Match risk to control: leakage of sensitive data points to DLP, lost media to encryption, known vulnerabilities to patching, lateral spread to segmentation, and ransomware recovery to offline or immutable backups.
- Hardening answers usually involve removing or disabling something: unused services, software, accounts and ports. Replace plaintext admin protocols (Telnet, FTP, HTTP) with encrypted ones (SSH, SFTP, HTTPS).
- Degaussing works only on magnetic media, never SSDs. Formatting is not sanitization. For SSDs use secure erase, crypto-erase or physical destruction, and always keep a certificate of destruction.
- Incremental: fastest backup, slowest restore (full + all incrementals). Differential: slower backup, faster restore (full + last differential). 3-2-1 means three copies, two media types, one off-site.
- The only way to know backups work is a test restore. Off-site protects against site disasters; on-site speeds everyday recovery. Frequency follows the RPO, restore speed must meet the RTO.
- RPO is about data loss (how far back), RTO is about downtime (how long). Hot is fastest and costliest, cold is slowest and cheapest. Synchronous means zero data loss but short distances; asynchronous allows distance with some loss.
- Higher MTBF is good (fails less often); lower MTTR is good (fixed faster). The BIA comes first and produces the priorities and objectives that DR plans implement.
Key terms
- Encryption at rest
- Encrypting stored data so it is unreadable without the key if media is stolen or copied.
- Encryption in transit
- Encrypting data as it travels across networks, for example with TLS or SSH.
- Data retention policy
- Rules specifying how long data is kept and when it must be destroyed.
- Data sovereignty
- The principle that data is subject to the laws of the country where it is physically stored.
- Access control vestibule (mantrap)
- A two-door entry space where only one door can open at a time, preventing tailgating.
- Tailgating
- Following an authorized person through a secure door without authenticating.
- Biometrics
- Authentication based on physical characteristics such as fingerprints or iris patterns.
- Clean agent suppression
- Fire suppression using gases that extinguish fire without water damage or residue on equipment.
- Least privilege
- Granting only the minimum permissions needed to perform a task.
- RBAC (role-based access control)
- Assigning permissions to roles and placing users in roles rather than granting rights individually.
- MFA
- Multifactor authentication: requiring two or more different types of authentication factors.
- Service account
- A non-human account used by an application or service to run and access resources.
- DLP (data loss prevention)
- Tools and policies that detect and block sensitive data from leaving authorized locations.
- Ransomware
- Malware that encrypts data and demands payment, often also stealing data for extortion.
- Insider threat
- Risk posed by people with legitimate access who misuse it maliciously or carelessly.
- Network segmentation
- Dividing a network into isolated zones to limit access and the spread of attacks.
- Attack surface
- All the points where an attacker could interact with or enter a system.
- Host-based firewall
- A firewall running on the server itself that filters its inbound and outbound traffic.
- EDR
- Endpoint detection and response: security software that monitors host behavior, detects threats and supports response.
- Security baseline
- A documented set of hardening settings that systems must meet.
- Wiping
- Overwriting all sectors of storage media so previous data cannot be recovered, allowing reuse.
- Degaussing
- Erasing magnetic media with a strong magnetic field, rendering hard drives unusable; ineffective on SSDs.
- Crypto-erase
- Sanitizing a self-encrypting drive by destroying its encryption key.
- Certificate of destruction
- A document confirming which media were destroyed, how, when and by whom.
- Incremental backup
- Copies data changed since the last backup of any type; restores need the full plus every incremental since.
- Differential backup
- Copies data changed since the last full backup; restores need the full plus the latest differential.
- Synthetic full
- A full backup assembled on the backup server from a prior full and later incrementals.
- Grandfather-father-son (GFS)
- A rotation scheme keeping daily, weekly and monthly backup sets for different retention periods.
- Retention period
- How long a backup copy is kept before it is expired and deleted.
- Off-site backup
- A backup copy stored at a different location to survive site-wide disasters.
- Test restore
- Restoring data from backup to verify the backup is complete and usable.
- Application-aware backup
- A backup that coordinates with an application so its data is captured in a consistent state.
- RPO
- Recovery point objective: the maximum acceptable amount of data loss, measured in time.
- RTO
- Recovery time objective: the maximum acceptable time to restore a service.
- Hot site
- A fully equipped recovery site with current data, ready to take over quickly.
- Synchronous replication
- Replication that confirms a write only after both sites have it, giving near-zero data loss at the cost of latency.
- BIA (business impact analysis)
- An analysis of business processes, their dependencies and the impact of their disruption over time.
- MTBF
- Mean time between failures: the average operating time between failures of a repairable item.
- MTTR
- Mean time to repair: the average time needed to restore a failed item or service.
- Communication plan
- The documented process and contacts for sharing information during an incident.
Domain 4: Troubleshooting (28%)
Exam tips
- Know the order and look for the step that was skipped. Question the obvious and ask what changed during step 1; back up before making changes; verify full functionality before documenting.
- Redundant parts failing do not stop the server, so the exam often asks for the next step: check the simple causes (cord, PDU, circuit), then hot-swap the part. Many servers overheating together suggests an environmental cause, not a single fan.
- With a degraded array, back up first and replace the correct drive. A sudden write slowdown on hardware RAID often means the cache battery failed and the controller dropped to write-through.
- Run fsck or chkdsk only on unmounted (or read-only) volumes and back up first. Extending a partition is not enough; the file system must be grown too.
- Gradual slowdown fixed by a reboot suggests a memory leak. A service that fails right after a password change points to its service account credentials. A crash after a new driver means roll back the driver.
- Application vs System vs Security logs is a common exam distinction: service and driver failures go to System, program errors to Application, logon events to Security. journalctl -u filters by service, -b by boot.
- Reach local hosts but nothing remote: check the gateway. Works by IP but not by name: check DNS. Slow with interface errors: suspect duplex mismatch. Ping works but one port fails: suspect a firewall rule.
- ping tests reachability, not ports; use Test-NetConnection, telnet or nc for ports. nslookup/dig for DNS, tracert/traceroute for the path, netstat/ss for what is listening, arp for IP-to-MAC mapping.
- For shares, effective access is the most restrictive of share and NTFS permissions, and explicit Deny wins. Fix security problems narrowly (a specific rule or exclusion) rather than disabling the control.
- Compare against a baseline to see what changed, and correlate logs by time. Watch for disguised bottlenecks: heavy paging from low memory often looks like a disk problem.
Key terms
- Theory of probable cause
- The best current explanation for a problem, formed after gathering information and tested before acting.
- Escalation
- Passing a problem to someone with more expertise or authority when you cannot resolve it.
- Preventive measures
- Actions taken after a fix to stop the same problem from happening again.
- Scope
- How widespread a problem is, such as one user, one server or an entire site.
- POST
- Power-on self-test: firmware checks run at startup that report hardware faults.
- Beep code
- A pattern of beeps at startup indicating a hardware error; meanings vary by vendor.
- Predictive failure
- An alert that a component, such as a drive, shows signs it is likely to fail soon.
- UID LED
- A unit identification light used to locate a specific server or component in a rack.
- Degraded array
- A RAID array that has lost a member but still serves data without redundancy.
- Write-back cache
- Controller caching that confirms writes before they reach disk; requires battery or flash protection.
- Write-through
- Caching mode that confirms writes only after they reach disk, safer but slower.
- fstab
- The Linux file that lists which file systems to mount at boot and where.
- chkdsk
- Windows tool that checks and repairs file system errors; /f fixes errors and /r also scans for bad sectors.
- fsck
- Linux file system consistency checker, run on unmounted file systems.
- smartctl
- A command-line tool that reads SMART health data from drives.
- parted
- A Linux partitioning tool that supports GPT disks and resizing.
- Memory leak
- A defect where a program keeps allocating memory without releasing it, gradually exhausting RAM.
- Runaway process
- A process consuming excessive CPU or resources, often stuck in a loop.
- Boot loop
- A condition where a system restarts repeatedly without completing startup.
- Service dependency
- Another service that must be running before a given service can start.
- Event Viewer
- The Windows tool for reading Application, System, Security and other event logs.
- journalctl
- The command for querying the systemd journal on Linux, filterable by unit, boot, priority and time.
- Performance Monitor
- The Windows tool that displays and logs performance counters over time.
- Safe mode
- A Windows startup mode that loads only essential drivers and services for troubleshooting.
- APIPA
- Automatic Private IP Addressing: a 169.254.x.x address a Windows host assigns itself when DHCP fails.
- Default gateway
- The router address a host uses to reach networks outside its own subnet.
- Duplex mismatch
- A link where one side runs full duplex and the other half duplex, causing errors and poor performance.
- Hosts file
- A local file that maps names to IP addresses and is checked before DNS on most systems.
- traceroute/tracert
- A tool that lists each router hop to a destination and the delay to each.
- nslookup/dig
- Tools that query DNS servers directly to check name resolution.
- ss/netstat
- Tools that list network connections and listening ports, optionally with the owning process.
- Test-NetConnection
- A PowerShell cmdlet that tests connectivity, including whether a TCP port is reachable.
- Effective permissions
- The actual access a user has after combining all group permissions, deny entries and share and NTFS permissions.
- Certificate chain
- The server certificate plus the intermediate certificates linking it to a trusted root.
- False positive
- A security tool flagging legitimate activity or files as malicious.
- Indicator of compromise
- Evidence, such as unusual logons or unknown services, suggesting a system or account has been breached.
- Root cause
- The underlying reason a problem occurred, which, when fixed, prevents recurrence.
- Performance counter
- A measured value, such as disk queue length or available memory, tracked by the OS or monitoring tools.
- Bottleneck
- The resource that limits overall performance because it is saturated.
- SIEM
- Security information and event management: a system that collects and correlates logs from many sources.
Study Server+ for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Server+ study planLessons, quizzes, exam simulations and hands-on labs.