Expect questions on laptops, tablets, smartphones and wearables, plus the ports and connectors that link them.
Networking questions on Core 2 (and touched in Core 1) cover cabling, wireless standards, IP addressing, ports and troubleshooting tools. Know the numbers cold.
A+ Core 2 tests Windows, macOS and Linux side by side. You need to know editions, file systems, command-line tools and how each OS handles users, updates and troubleshooting.
Physical controls stop the wrong person getting hands on a device or a room. Know these: badge readers, biometrics (fingerprint, retina, facial), mantraps (one person through at a time, stops tailgating), equipment locks (cable locks, laptop locks), server room access lists, and privacy/security screens (stop shoulder surfing). A guard or receptionist checking ID is a physical control too. Common mistake: candidates mix up 'tailgating' (an unauthorised person follows an authorised one through a door) with 'shoulder surfing' (watching someone type a password or PIN) - they are different attack types and both appear on the exam.
AAA stands for Authentication, Authorisation, Accounting. Multifactor authentication (MFA) needs at least two different factor TYPES: something you know (password, PIN), something you have (smart card, authenticator app, hardware token), something you are (biometrics), somewhere you are (location), something you do (behaviour). Two passwords is NOT MFA - it is just two knowledge factors. Least privilege means giving users only the access they need to do their job, nothing more. Principle of least privilege plus role-based access control (RBAC) are the standard model for assigning permissions.
Know the malware family: virus (needs a host file, needs user action to spread), worm (self-replicates across a network with no user action), trojan (disguised as legitimate software), ransomware (encrypts files and demands payment), spyware/keylogger (steals data or keystrokes), rootkit (hides deep in the OS, hard to detect). Social engineering attacks to know: phishing (email), vishing (voice/phone), smishing (SMS text), shoulder surfing, tailgating, dumpster diving, and whaling (phishing aimed at a senior executive). Common mistake: calling every email-based attack 'phishing' when the exam may specifically ask for spear phishing (targeted at one person/org) versus whaling (targeted at a C-level exec).
Wi-Fi encryption order from weakest to strongest: WEP (broken, never use), WPA, WPA2 (AES/CCMP), WPA3 (current standard, adds SAE for stronger handshake security). Always recommend WPA3, or WPA2 with AES if WPA3 isn't supported. A firewall filters traffic by port/protocol/IP; a VPN encrypts traffic over an untrusted network. Know that changing the default SSID and default admin password on a router are basic hardening steps, and that disabling SSID broadcast is weak security theatre, not a real control.
Know full device encryption, remote wipe, and screen locks (PIN/pattern/biometric) as core mobile protections. Data destruction methods: standard formatting is NOT secure erasure - use low-level format/overwrite, degaussing (magnetic media only, useless on SSDs), or physical destruction (shredding/drilling) for guaranteed disposal, especially for regulated data.
CompTIA tests a fixed six-step process. Learn the order, not just the steps.
1. Identify the problem - gather info, question the user, identify symptoms, check for changes, duplicate the problem if possible, approach multiple problems individually.
2. Establish a theory of probable cause - start with the obvious (Occam's razor), question the obvious.
3. Test the theory to determine cause - once confirmed, decide next steps. If not confirmed, re-theorise or escalate.
4. Establish a plan of action and implement the solution - research the knowledge base if needed.
5. Verify full system functionality and implement preventive measures if needed.
6. Document findings, actions, and outcomes.
Questions often give you a scenario and ask 'what is the NEXT step' - map the scenario to the six steps in order and pick the very next one, not the best overall action.
Electrostatic discharge (ESD) is the top hazard for components. Always wear an anti-static wrist strap connected to a grounded point, and use anti-static bags for storage and transport. If no strap is available, self-ground by touching the case chassis before touching parts.
Electrical safety matters just as much. Always unplug a device before opening the case. When working inside a power supply or CRT monitor, never open the casing yourself - these hold a lethal charge even when unplugged, so leave them to trained techs. Use an ESD mat on the workbench to protect components further.
Know your fire extinguisher classes. Class A is for ordinary combustibles like wood and paper. Class B is for flammable liquids. Class C is for electrical fires - never use water or a Class A extinguisher on live electrical equipment. Class D is for combustible metals. A Class ABC extinguisher covers most office and workshop situations.
When lifting heavy equipment such as a server or printer, lift with your legs not your back, keep the load close to your body, and get help or a trolley for anything over roughly 40 lbs (about 18 kg). Poor posture at a workstation causes long-term injury, so keep monitors at eye level and use proper chair support.
Environmental controls matter for equipment longevity: keep humidity moderate to avoid ESD (too dry) or corrosion (too damp), and keep temperature controlled with good airflow. Material Safety Data Sheets (MSDS), now called SDS (Safety Data Sheets), tell you how to handle hazardous materials safely and what to do in an incident - know where to find them.
Dispose of batteries, toner cartridges, and CRT monitors according to local regulations - never in general rubbish, since they contain hazardous materials. Follow your organisation's environmental policy for e-waste recycling.
A+ techs must show good professional behaviour: maintain a positive attitude, avoid jargon with customers, actively listen, avoid distractions like personal calls while working, and set clear, realistic expectations with the customer. Deal with difficult customers or situations calmly and without arguing.