220-1102 exam dumps

220-1102 practice question 365 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 365

Single answerStandard account

A user on a Windows 11 laptop says they can open company applications and save files normally, but they cannot install a new printer driver or change system-wide network settings. The user is signed in with a standard account, and company policy is to follow least-privilege security practices. Which action should the technician take FIRST to complete the requested task while maintaining security best practices?

  1. A

    Change the user's account type to Administrator so they can complete the installation and settings changes themselves

  2. B

    Sign in with or provide administrator credentials only for the required administrative task, while leaving the user as a standard account

  3. C

    Disable User Account Control so the standard account can install drivers and modify network settings without prompts

  4. D

    Create a second standard account for the user and use it to perform the printer driver installation

Show answer and explanation

Correct answer: B

Explanation

In Windows, a standard account is designed for routine tasks such as running applications, browsing, and working with files, but it cannot perform administrative actions like installing many device drivers or changing system-wide settings without elevation. The correct first step is to use administrator credentials only for the specific task, rather than permanently promoting the user to an administrator. This follows the security best practice of least privilege, which is emphasized in enterprise support and Microsoft account management guidance. User Account Control exists specifically to support this model by prompting for consent or credentials when elevated rights are required. Keeping users as standard accounts helps reduce malware impact and accidental system misconfiguration.

  • A. Incorrect.

    This is incorrect because changing the user's account type to Administrator grants ongoing elevated privileges beyond what is needed for the task. That violates the principle of least privilege and increases security risk. A common misconception is that making a user an administrator is the easiest fix, but it is not the preferred or safest approach in managed environments.

  • B. Correct.

    This is correct because standard accounts are intended for everyday work and should not have permanent permission to install drivers or make system-wide changes. The best practice is to use administrative credentials only when elevation is required, such as through User Account Control prompts or an administrator performing the task. This preserves security while still allowing the necessary change.

  • C. Incorrect.

    This is incorrect because disabling User Account Control reduces an important layer of protection and does not align with security best practices. UAC helps prevent unauthorized system changes by requiring approval or administrator credentials for elevated actions. Turning it off to bypass permissions is a poor security decision.

  • D. Incorrect.

    This is incorrect because a second standard account still would not have the permissions needed to install printer drivers or change system-wide network settings. Someone might choose this option if they confuse account separation with privilege elevation, but a standard account remains limited regardless of how many standard accounts exist.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam