A+ Core 2 Exam Objectives (220-1202): All Four Domains, Weighted

This is the full 220-1202 objectives list with CompTIA's official weights, plus what a plain copy of the objectives leaves out: what each one actually asks of you, and where the marks concentrate. Three things worth knowing before you plan. Operating Systems and Security are tied at 28% each, together 56% of the exam. 64% of the sub-objectives are scenario-phrased, well above Core 1. And the pass mark is 700, not Core 1's 675.

Exam220-1202
QuestionsMax 90
Time90 minutes
Pass mark700 / 900
Sub-objectives36
Your free A+ Core 2 exam code

See your score broken down by these exact domains

The objectives tell you what is testable. A full-length practice exam tells you which parts of it you cannot do yet - which matters more on Core 2 than on any other CompTIA exam, because two thirds of it is scenarios. Free, with an explanation and an Exam Tip on every item.

APLUS2-EXAM-FULL Start the free exam

Already have an account? Log in to start · Prefer a 5-question taster? Try the short version.

Where the marks are

1.0 Operating Systems
28%
2.0 Security
28%
3.0 Software Troubleshooting
23%
4.0 Operational Procedures
21%

This is a remarkably flat blueprint - just seven points separate the largest domain from the smallest. Which means the weights alone tell you very little about where to spend your time. Divide by the number of sub-objectives and the picture changes completely:

DomainWeightSub-objectivesMarks per objectiveScenario-based
3.0 Software Troubleshooting23%45.84 of 4
1.0 Operating Systems28%112.57 of 11
2.0 Security28%112.57 of 11
4.0 Operational Procedures21%102.15 of 10

Two conclusions, and the second one is the one that catches people out:

  • Software Troubleshooting is concentrated, not cheap. Four sub-objectives for 23% of the exam is more than twice the marks-per-objective of anything else - but all four are "Given a scenario", so you cannot bank them by reading. It is the highest-value content and the least crammable, simultaneously.
  • Operational Procedures is not filler. At 21% it is barely smaller than Security, and it is the most learnable domain on the exam - safety, environmental controls, licensing and privacy, scripting basics, professionalism and the AI objective are largely definitional. Technical candidates skim it and lose a fifth of the paper.

How to read the objectives

CompTIA prefixes each sub-objective with a verb phrase telling you the depth expected. On Core 2 the signal is stark: 23 of the 36 sub-objectives - 64% - begin with "Given a scenario", against 48% on Core 1.

  • "Given a scenario…" - apply it to a situation. These are the sub-objectives most likely to become performance-based questions, and reading about them prepares you badly. They need practice.
  • "Explain…" / "Summarize…" / "Identify…" - understanding and recall. Reading genuinely suffices, and this is where the fast marks live.
  • "Compare and contrast…" - the boundaries between similar things, which is exactly where distractors come from. Expect four plausible options from the same family.
What this means in practice. Core 2 has a reputation for being the easier of the two exams because the content feels more familiar - everyone has used Windows. The objectives say the opposite about how to prepare: a higher pass mark, more sub-objectives, and two thirds of them demanding application rather than recall. Familiarity with Windows is not the same as being able to fix it against a clock.

The four domains, objective by objective

28%

1.0 Operating Systems11 sub-objectives, joint-largest. Six are explicitly Microsoft Windows.

  • 1.1Explain common operating system types and their purposesWorkstation, mobile, and embedded operating systems, filesystem types, vendor lifecycle and compatibility concerns. Definitional and quick.
  • 1.2Given a scenario, perform OS installations and upgrades in a diverse environmentBoot methods, installation types including clean install, in-place upgrade, image deployment and recovery partition, partitioning schemes and filesystem selection. A strong PBQ candidate.
  • 1.3Compare and contrast basic features of Microsoft Windows editionsEdition differences, feature availability and upgrade paths. Pure recall, and questions here are usually "which edition supports this feature".
  • 1.4Given a scenario, use Microsoft Windows features and toolsTask Manager, MSConfig, Disk Management, Device Manager, Event Viewer, the MMC snap-ins and the rest of the administrative toolset. Know which tool solves which problem - that is the question format almost every time.
  • 1.5Given a scenario, use the appropriate Microsoft command-line toolsNavigation (cd, dir), network (ipconfig, ping, netstat, nslookup, net use, tracert, pathping), disk (chkdsk, format, diskpart), file (md, rmdir, robocopy), informational (hostname, net user, winver, whoami) and OS management (gpupdate, gpresult, sfc). The full command reference, Windows and Linux.
  • 1.6Given a scenario, configure Microsoft Windows settingsControl Panel and Settings utilities, user accounts, power options, display and system configuration. Broad, shallow, and mostly navigable if you have used Windows administratively.
  • 1.7Given a scenario, configure Windows networking features on a client or desktopWorkgroup and domain membership, network shares and printers, network locations, proxy settings, firewall configuration and VPN clients. Pairs directly with Core 1's networking domain.
  • 1.8Explain common features and tools of macOSFinder, Time Machine, Disk Utility, Keychain, Spotlight, Mission Control, System Settings, and the installation and update model. One objective for an entire operating system - learn the tool names and what each does, not the depth.
  • 1.9Identify common features and tools of the Linux client or desktopFile management (ls, pwd, mv, cp, rm, chmod, chown, grep, find), filesystem (fsck, mount), administrative (su, sudo), package management (apt, dnf), network (ip, ping, curl, dig, traceroute), informational (man, cat, top, ps, du, df), nano, and the key configuration files - /etc/passwd, /etc/shadow, /etc/hosts, /etc/fstab, /etc/resolv.conf. Note the verb is "identify", the shallowest on the exam.
  • 1.10Given a scenario, install applications according to requirementsSystem requirements, OS compatibility, distribution methods, and the impact of an install on the device, network and business. More about the checks before installing than the clicking.
  • 1.11Given a scenario, install and configure cloud-based productivity toolsAccount setup, synchronisation, licensing and access. New emphasis in this generation of the exam, and light on detail.
28%

2.0 Security11 sub-objectives. Broad but shallow - this is not Security+.

  • 2.1Summarize various security measures and their purposesPhysical security, logical security, authentication and MFA, and access control concepts. The vocabulary the rest of the domain assumes.
  • 2.2Given a scenario, configure and apply basic Windows OS security settingsUser and group management, NTFS versus share permissions, UAC, BitLocker and EFS. Permissions questions are a classic PBQ - know what happens when share and NTFS permissions conflict.
  • 2.3Compare and contrast wireless security protocols and authentication methodsWPA2 and WPA3, TKIP and AES, and enterprise authentication with RADIUS and TACACS+. Short, recall-based, reliably tested.
  • 2.4Summarize types of malware and tools and methods for detection, removal and preventionMalware categories and the tooling. Learn the categories precisely - the distinction between a worm, a trojan and a rootkit is exactly what distractors are built from.
  • 2.5Compare and contrast common social engineering attacks, threats and vulnerabilitiesPhishing and its variants, impersonation, tailgating, shoulder surfing, plus the technical threats - DoS, on-path, spoofing, zero-day. Recall-heavy and quick to bank.
  • 2.6Given a scenario, implement procedures for basic SOHO malware removalThe removal process in order: investigate and verify, quarantine, remediate, schedule scans and updates, enable System Restore, educate the user. The order is the question - learn it as a sequence, not a list.
  • 2.7Given a scenario, apply workstation security options and hardening techniquesPassword policies, account management, autorun and autoplay, patching and update policy, and endpoint hardening.
  • 2.8Given a scenario, apply common methods for securing mobile devicesScreen locks, remote wipe, encryption, MDM policies, app source restriction and the corporate versus personal device distinction.
  • 2.9Compare and contrast common data destruction and disposal methodsPhysical destruction - shredding, drilling, degaussing, incineration - versus sanitization such as erasing, wiping and low-level formatting, plus certificates of destruction. Definitional and reliably examined.
  • 2.10Given a scenario, apply security settings on SOHO wireless and wired networksChanging defaults, firmware updates, guest networks, firewall and port forwarding, DHCP reservations and content filtering. The natural PBQ pairing with Core 1's 2.6.
  • 2.11Given a scenario, configure relevant security settings in a browserTrusted and untrusted sources, extension and plug-in management, password managers, certificate handling, pop-up and ad blockers, private browsing and cache clearing.
23%

3.0 Software TroubleshootingOnly 4 sub-objectives for 23% - and all four are "Given a scenario".

  • 3.1Given a scenario, troubleshoot common Windows OS issuesBoot failures, blue screens, slow performance, application crashes, profile problems, update failures, and the repair tooling. The single heaviest sub-objective on Core 2 by weight.
  • 3.2Given a scenario, troubleshoot common mobile OS and application issuesApp crashes and freezes, update failures, battery and performance problems, connectivity faults.
  • 3.3Given a scenario, troubleshoot mobile OS and application security issuesIndicators of compromise on mobile - unexpected data usage, unauthorised access, high resource consumption, fake security warnings, leaked personal data. Note this is a separate objective from 3.2: CompTIA splits mobile faults from mobile compromise, and so should your revision.
  • 3.4Given a scenario, troubleshoot common PC security issuesSymptoms of infection, browser redirects and hijacking, certificate warnings, altered system files and settings, and the remediation path. Applies 2.6's removal sequence to a described situation.
21%

4.0 Operational Procedures10 sub-objectives. The most learnable content on the exam, and the most skipped.

  • 4.1Given a scenario, implement best practices for documentation and support systemsTicketing systems, asset management, knowledge base articles, network topology diagrams, acceptable use and standard operating procedures.
  • 4.2Given a scenario, apply change management proceduresDocumented business processes, purpose and scope of change, risk analysis, change board approval, end-user acceptance, rollback plan. Dry, and reliably examined - learn the stages in order.
  • 4.3Given a scenario, implement workstation backup and recovery methodsBackup types - full, incremental, differential, synthetic - rotation schemes, on-site versus off-site, and the 3-2-1 rule. Know what a restore actually requires from each backup type; that is the question.
  • 4.4Given a scenario, use common safety proceduresESD straps and mats, equipment grounding, safe lifting, electrical fire safety, personal safety and compliance with government regulations.
  • 4.5Summarize environmental impacts and local environment controlsMaterial safety data sheets and disposal, temperature and humidity, ventilation, and power protection with surge suppressors, battery backup and generators.
  • 4.6Explain the importance of prohibited content and activity, privacy, licensing and policyIncident response for prohibited content including chain of custody and first response, licensing models - open source, commercial, personal versus enterprise - regulated data types and data retention.
  • 4.7Given a scenario, use proper communication techniques and professionalismClear language, active listening, cultural sensitivity, punctuality, difficult customers, setting expectations, confidentiality. The most "soft" content on the exam and among the most predictably marked - the correct answer is almost always the most patient and least assumptive one.
  • 4.8Explain the basics of scriptingScript file types, use cases such as basic automation, driver installation and backups, and the risks of running scripts including unintentional system changes. You do not need to write scripts, only to recognise types and reason about consequences.
  • 4.9Given a scenario, use remote access technologiesRDP, VPN, SSH, RMM tools, screen sharing and third-party remote access, plus the security considerations of each.
  • 4.10Explain basic concepts related to artificial intelligenceApplication integration; policy including appropriate use and plagiarism; limitations including bias, hallucinations and accuracy; and private versus public covering data security, data source and data privacy. New in this generation, entirely recall, and missing from a great deal of older study material - which makes it easy marks for anyone who knows it is there.
Your free A+ Core 2 exam code

Two thirds of this exam is scenarios. Practise them.

A checklist tells you everything matters. One full-length attempt tells you which sub-objectives are actually costing you marks - and on an exam where 23 of 36 objectives demand application, that difference is the whole preparation. Free, no credit card.

APLUS2-EXAM-FULL Redeem the code

Already have an account? Log in to redeem

What to study first

On a blueprint this flat, sequencing matters more than weighting. A sequence that works on Core 2:

  1. Operational Procedures, first and properly. 21% of the exam, and its most valuable objectives - safety, environmental, licensing and privacy, scripting basics, AI - are recall. This is the highest marks-per-hour content on the paper and the most commonly skipped. Do not leave it to the last week.
  2. Then the recall parts of Security (2.1, 2.3, 2.4, 2.5, 2.9). Five definitional objectives inside the joint-largest domain. Bank them before touching the scenario objectives around them.
  3. Then Windows properly (1.3 to 1.7). Five objectives, and everything in Domain 3 troubleshoots them. Learning the tools first makes the troubleshooting domain a fraction of the work it would otherwise be. Give the command-line tools in 1.5 real attention - they recur throughout Domain 3.
  4. macOS and Linux together (1.8, 1.9), in one sitting. One objective each, both shallow verbs. Learn tool names and what they do; resist the urge to go deeper than "identify" requires.
  5. The malware removal sequence (2.6), as a sequence. It reappears in 3.4, so learning the order once pays twice.
  6. Then Domain 3, entirely as practice. 23% of the exam across four scenario objectives. There is no reading that substitutes for working through faults.
💡
On taking Core 1 and Core 2. You need both to be A+ certified and they can be sat in either order. Many candidates find Core 2 the harder preparation despite the more familiar subject matter, for the reasons above - a higher pass mark, more sub-objectives and far more scenario content. The Core 1 objectives, weighted the same way.

Frequently asked questions

What are the A+ Core 2 domains and their weights?

Four domains: Operating Systems 28%, Security 28%, Software Troubleshooting 23%, and Operational Procedures 21%. Operating Systems and Security are tied as the largest, and together they are 56% of the exam. It is a notably flat blueprint - only seven points separate largest from smallest.

How many questions are on A+ Core 2?

A maximum of 90 questions in 90 minutes, mixing multiple choice with drag-and-drop and performance-based questions. The pass mark is 700 on a 100 to 900 scale, which is higher than Core 1's 675. The exam is scaled, so 700 cannot be converted into a number of correct answers.

How much of Core 2 is scenario based?

Twenty-three of 36 sub-objectives, about 64% - considerably more than Core 1's 48%. All four sub-objectives in Software Troubleshooting carry the phrasing, as do seven of eleven in both Operating Systems and Security. Core 2 rewards practice over reading more than any other CompTIA entry-level exam.

Is there an AI objective on the A+ exam?

Yes, objective 4.10, "Explain basic concepts related to artificial intelligence". It covers application integration, policy including appropriate use and plagiarism, limitations including bias, hallucinations and accuracy, and private versus public covering data security, data source and data privacy. It is recall content and easy marks - but it is absent from a lot of older study material, so people miss it entirely.

Which domain should I study first?

Operational Procedures, despite being smallest. Its content is largely definitional, which makes it the highest marks-per-hour on the exam, and it is the domain technical candidates most reliably skip. Then the recall objectives inside Security, then Windows, and leave Software Troubleshooting until you know the systems it troubleshoots.

How much of Core 2 is Windows?

Most of Domain 1. Six of eleven Operating Systems sub-objectives are explicitly Microsoft Windows, plus an explicitly Windows security objective in Domain 2, and Domain 3's heaviest objective troubleshoots Windows. macOS and Linux get one sub-objective each, both with shallow verbs. Windows is comfortably the largest single subject on the exam.

Which should I take first, Core 1 or Core 2?

Either - CompTIA does not impose an order, and you need both to certify. Core 1's networking content does make some of Core 2's Windows networking objective easier, which is a mild argument for Core 1 first. The stronger consideration is that Core 2 has a higher pass mark and more scenario content, so leaving it second means preparing for the harder exam while your first pass is still fresh.