220-1102 exam dumps

220-1102 practice question 163 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 163

Single answerAccounts

A small office uses Windows 11 Pro PCs that are joined to Microsoft Entra ID (Azure AD). A user reports that after being promoted, they need to install approved line-of-business applications that require local administrative rights on only their assigned laptop. Company policy prohibits giving users domain-wide admin privileges or sharing built-in Administrator credentials. Which action should the technician take to meet the requirement while following least-privilege best practices?

  1. A

    Add the user’s Microsoft Entra account to the local Administrators group on that specific laptop

  2. B

    Add the user to the Domain Admins group so app installations will work on all company devices

  3. C

    Enable the built-in local Administrator account and give the password to the user when needed

  4. D

    Change the user’s account type to Standard user to reduce UAC prompts during installations

Show answer and explanation

Correct answer: A

Explanation

The best solution is to grant administrative rights only on the specific device that requires them by adding the user to that PC’s local Administrators group. In Windows environments, local group membership can be used to provide device-specific privileges without assigning broad enterprise-level authority. This aligns with standard security guidance around least privilege and role-based access control. Options such as Domain Admins or sharing the built-in Administrator account create unnecessary security exposure and are not appropriate for routine endpoint administration. Microsoft security best practices consistently recommend limiting privileged access, avoiding shared admin credentials, and granting the minimum rights necessary for the task.

  • A. Correct.

    Correct. Adding the user’s account to the local Administrators group on only the required device grants the necessary elevated rights for that machine without assigning excessive permissions elsewhere. This follows the principle of least privilege because the user receives only the access needed to perform approved tasks on a single endpoint.

  • B. Incorrect.

    Incorrect. Domain Admins is a highly privileged group intended for broad administrative control of the environment, not for routine software installation by an end user. This would violate least-privilege practices and create unnecessary risk if the account were compromised.

  • C. Incorrect.

    Incorrect. Sharing credentials for the built-in Administrator account is poor security practice because it removes accountability, increases the risk of credential exposure, and bypasses proper role-based access control. The scenario specifically states that sharing the built-in Administrator credentials is prohibited.

  • D. Incorrect.

    Incorrect. A Standard user has fewer privileges, not more. Changing the user to Standard user would make software installations that require elevation less likely to succeed and does not address the need for approved administrative capability.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam