220-1102 exam dumps

220-1102 practice question 336 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 336

Single answerPrinciple of least privilege

A small accounting firm is tightening security after discovering that several users have local administrator rights on their Windows 11 PCs. One employee in Accounts Payable needs to use a legacy invoicing application that requires elevated privileges only when installing monthly vendor updates. The employee should not be able to change system-wide settings or install unrelated software during normal daily work. Which action BEST follows the principle of least privilege while still allowing the updates to be performed?

  1. A

    Make the employee a local administrator so the application and updates always run without interruption

  2. B

    Create a separate standard user account for daily work and use an administrator account only when the vendor update must be installed

  3. C

    Disable User Account Control (UAC) so the application can update without prompting for credentials

  4. D

    Give the employee Power User permissions so they can update the application but not affect the operating system

Show answer and explanation

Correct answer: B

Explanation

The principle of least privilege means assigning users the minimum permissions required to perform their job and elevating rights only when necessary. In this scenario, the best practice is to keep the employee in a standard user context for normal work and use administrative credentials only for the specific task that requires elevation, such as installing the monthly vendor update. This reduces the attack surface, limits accidental system changes, and aligns with common security guidance from Microsoft and general endpoint security best practices. Options that broadly grant administrative rights or weaken controls like UAC increase risk and do not follow least-privilege design.

  • A. Incorrect.

    This is incorrect because making the employee a local administrator grants broad rights well beyond what is needed for monthly updates. That violates the principle of least privilege by allowing unnecessary access to install software, change security settings, and modify system configuration.

  • B. Correct.

    This is correct because it limits the employee to standard user rights for routine work and uses elevated credentials only when administrative tasks are required. That is a practical implementation of least privilege: users receive only the minimum access necessary for their job functions, with elevation used only for specific approved tasks.

  • C. Incorrect.

    This is incorrect because disabling UAC reduces an important Windows security control and does not implement least privilege. UAC helps prevent unauthorized or accidental administrative changes by requiring approval or credentials when elevated actions are attempted.

  • D. Incorrect.

    This is incorrect because Power Users is not an appropriate modern solution for Windows 10/11 privilege management. In current Windows environments, relying on standard user accounts and administrative elevation is the recommended approach. Choosing Power Users reflects an outdated understanding of Windows permissions.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam