220-1102 exam dumps

220-1102 practice question 171 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 171

Single answerApplication restrictions and exceptions

A company uses Windows 10/11 Pro laptops for its accounting staff. To reduce malware risk, the IT department has configured local security policy so only approved applications can run. After a payroll software update, users report that the application launches, but its built-in updater fails because it needs to start a new executable from a subfolder under C:\Program Files\ContosoPayroll\Updater. Management wants the updater to work without allowing users to run other unauthorized software. Which action is the BEST way to resolve this issue?

  1. A

    Disable application restrictions on the affected laptops so the updater can run normally

  2. B

    Create an additional allow rule for the updater executable in the approved application restriction policy

  3. C

    Add the accounting users to the local Administrators group so the updater can bypass the restriction

  4. D

    Move the updater executable to the users' Downloads folder and instruct users to run it manually when prompted

Show answer and explanation

Correct answer: B

Explanation

The best solution is to modify the application restriction configuration to explicitly allow the legitimate updater executable and nothing more. In Windows environments, application control is commonly implemented with AppLocker or Software Restriction Policies. Best practice is to maintain a default-deny or approved-list approach, then add narrowly scoped exceptions for required business applications. This minimizes attack surface while restoring functionality. Disabling restrictions or granting admin rights would be excessive and introduce unnecessary risk. Microsoft documentation for AppLocker and Software Restriction Policies supports using specific allow rules, ideally scoped by publisher, path, or file hash as appropriate for the environment.

  • A. Incorrect.

    This is incorrect because disabling the application restriction policy removes the control that was specifically put in place to reduce malware risk. It solves the immediate problem but violates the requirement to keep unauthorized software blocked.

  • B. Correct.

    This is correct because application restriction technologies such as AppLocker or Software Restriction Policies are designed to allow approved applications and make targeted exceptions when a legitimate executable is blocked. Creating a specific allow rule for the payroll updater preserves the security baseline while permitting the required business function.

  • C. Incorrect.

    This is incorrect because administrator rights do not automatically override application restriction policy. In addition, granting accounting users local admin access greatly increases security risk and does not meet the goal of allowing only the specific updater.

  • D. Incorrect.

    This is incorrect because the Downloads folder is a common user-writable location and is typically less trusted. Moving the executable there weakens security and encourages a manual workaround rather than properly updating the application control policy.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam