A+ Lesson

Defender Antivirus and Firewall Settings for A+

Last updated: 6/10/2026

Short answer

Technicians must be able to open the Windows Security app (or Control Panel firewall settings), verify that Defender is running and that definition/engine updates occurred recently, and confirm firewall state and allowed applications. Key checks include last update time, real-time protection toggle, and firewall profile (Domain/Private/Public) currently active.

Why it appears on the exam

- Identify where to check Defender update timestamp and what it implies. - Given a scenario where an application fails to receive incoming connections, decide whether a firewall rule or profile setting is the likely cause. - Recognize whether Defender will run alongside a particular third-party AV tool (basic identification).

Key concepts

Concept 1

Required terms

Defender Antivirus: Built-in Windows anti-malware component that scans, quarantines, and reports threats; must be active and receive definition updates for protection. Windows Firewall: Host-based firewall that enforces inbound/outbound rules by profile (Domain/Private/Public) and can block ports or applications. Defender Antivirus: built-in anti-malware, scan/quarantine, needs definition updates. Windows Firewall: host firewall enforcing rules by profile and application/port.

Example

Verifying "Virus & threat protection" shows latest update and real-time protection is on.

Concept 2

How Defender Antivirus and Firewall Settings works

Technicians must be able to open the Windows Security app (or Control Panel firewall settings), verify that Defender is running and that definition/engine updates occurred recently, and confirm firewall state and allowed applications. Key checks include last update time, real-time protection toggle, and firewall profile (Domain/Private/Public) currently active.

Example

Confirming firewall "Allowed apps" includes the expected program or that a port is blocked by default on Public profile.

Concept 3

Common confusion

Tendency to assume Defender is off when a third-party antivirus was previously installed; Windows may disable Defender automatically. Also confusion between network-level firewall (router) and Windows Firewall; Windows Firewall protects the host and uses profiles affecting behavior.

Example

Verifying "Virus & threat protection" shows latest update and real-time protection is on.

Concept 4

Core 2 (220-1202) question cues

Identify where to check Defender update timestamp and what it implies; Given a scenario where an application fails to receive incoming connections, decide whether a firewall rule or profile setting is the likely cause; Recognize whether Defender will run alongside a particular third-party AV tool (basic identification).

Example

Confirming firewall "Allowed apps" includes the expected program or that a port is blocked by default on Public profile.

Sample questions

Select an answer to reveal the explanation. For tracked practice and weak-area review, use the Cultiv8 app.

Q1.A technician is troubleshooting this situation: Verifying "Virus & threat protection" shows latest update and real-time protection is on. What should they identify?

Q2.A technician sees this situation: Confirming firewall "Allowed apps" includes the expected program or that a port is blocked by default on Public profile. Which answer should they choose?

Q3.Read this A+ scenario: Host-based firewall that enforces inbound/outbound rules by profile (Domain/Private/Public) and can block ports or applications. Which term or action matches it?

Practice this lesson in Cultiv8

The app adds tracked practice, targeted remediation, saved session history, and future readiness scoring.

Continue in Cultiv8