1.0 Operating Systems — 28%
Operating Systems covers installation, configuration, command-line and GUI tools, files and permissions, storage, networking, updates, recovery, applications, and cross-platform support. The objective is not to memorize every menu location. You should know which tool or setting exposes the evidence needed for a task and what changes when a system is joined to an organizational management environment.
Study priority: perform the same basic support tasks on at least two platforms: inspect IP settings, processes, services, storage, users, permissions, logs, updates, startup behavior, and installed applications. Note which tasks are conceptually the same even when the commands differ. Build a recovery ladder that starts with the least destructive action and ends with reinstallation only when the evidence justifies it.
2.0 Security — 28%
Security is tied for the largest domain because endpoint support constantly touches identity, permissions, malware, encryption, authentication, physical safeguards, browser and application risk, data handling, and organizational policy. A support technician is often the first person to see suspicious behavior, so the correct action may be to contain or escalate rather than simply repair the visible symptom.
Study priority: map threats to controls and response steps. Practice account security, least privilege, MFA, permission review, patching, endpoint protection, browser hardening, removable-media handling, device encryption, secure disposal, and safe wireless configuration. For each malware scenario, distinguish symptoms, immediate containment, evidence considerations, cleanup, recovery, and user follow-up.
3.0 Software Troubleshooting — 23%
Software Troubleshooting covers boot issues, application failures, performance problems, malware symptoms, browser problems, mobile issues, and user-experience failures. Strong troubleshooting starts by narrowing the scope: one user or all users, one application or the system, local or network-dependent, recent change or long-standing issue, repeatable or intermittent.
Study priority: build a symptom matrix for slow startup, application crash, service failure, high resource use, login trouble, browser redirects, update failures, missing files, permission errors, and mobile synchronization problems. For every symptom, identify the first observation that would separate configuration, corruption, resource exhaustion, permissions, network dependency, and security compromise.
4.0 Operational Procedures — 21%
Operational Procedures covers documentation, change management, backup and recovery, safety, environmental controls, professionalism, privacy, licensing, scripting concepts, remote support, escalation, and incident handling. This domain turns technical skill into support that another person can understand and an organization can trust.
Study priority: document your own labs using a ticket format: user impact, scope, evidence, theory, action, risk, validation, and closure notes. Practice explaining a technical issue to a nontechnical user without blaming them. Review when a change needs approval, when data must be protected or destroyed, when a problem should be escalated, and when safety procedures override speed.