220-1102 exam dumps

220-1102 practice question 3 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 3

Single answerWindows

A technician is preparing a Windows 11 laptop for a remote employee who frequently travels and uses public Wi-Fi. The user must be able to sign in to the laptop if internet access is unavailable, but the company also wants to reduce the risk of password compromise and avoid managing separate local passwords. Which sign-in configuration should the technician recommend?

  1. A

    Create a local account with no password so the user can always sign in offline

  2. B

    Join the PC to a workgroup and require a BIOS password for authentication

  3. C

    Sign in with a Microsoft account and configure Windows Hello PIN

  4. D

    Enable Guest access and require the user to switch accounts after connecting to Wi-Fi

Show answer and explanation

Correct answer: C

Explanation

The best answer is to sign in with a Microsoft account and configure Windows Hello PIN. In Windows 10 and Windows 11, users can sign in with a Microsoft account and continue to log in even when offline because Windows caches the necessary credentials locally. Windows Hello PIN is a preferred option because it is device-specific, unlike a traditional password that can be reused across services if compromised. This makes it especially suitable for mobile users who may work without reliable internet access and who face increased risk on public networks. Microsoft documentation and security guidance consistently recommend Windows Hello as a more secure sign-in method than passwords for supported Windows systems.

  • A. Incorrect.

    This is incorrect because removing the password from a local account significantly weakens security, especially for a traveling user. While a local account can support offline sign-in, the scenario specifically states the company wants to avoid managing separate local passwords and reduce password-compromise risk.

  • B. Incorrect.

    This is incorrect because a workgroup does not provide user authentication benefits for this scenario, and a BIOS/UEFI password is not a replacement for Windows account sign-in. BIOS passwords help restrict device startup or firmware access, but they do not provide the Windows identity and account protections requested.

  • C. Correct.

    This is correct because a Microsoft account supports Windows sign-in and can still authenticate locally when the device is offline using cached credentials. Configuring a Windows Hello PIN improves security and convenience because the PIN is tied to that specific device rather than being the user's reusable account password. This aligns with Microsoft best practices for stronger, device-bound sign-in methods on Windows 10/11.

  • D. Incorrect.

    This is incorrect because the Guest account is not an appropriate secure sign-in solution for a business user. It does not meet the requirement for a personalized, secure account and would create major security and auditing concerns. It also does not address the need to reduce password-compromise risk.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam