220-1102 exam dumps

220-1102 practice question 366 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 366

Single answerAdministrator

A help desk technician needs to install a legacy accounting application on a Windows 11 Pro workstation. The application installer requires elevated privileges, but company policy prohibits giving the technician's standard user account permanent local administrator rights. The workstation is joined to a workgroup, not a domain. Which of the following is the BEST way to complete the installation while following security best practices?

  1. A

    Sign in with the built-in Administrator account and leave it enabled for future software installs

  2. B

    Add the technician's user account to the local Administrators group, install the application, and remove the account afterward

  3. C

    Use Run as administrator with local administrator credentials only for the installer

  4. D

    Disable User Account Control (UAC), run the installer from the technician's standard account, and re-enable UAC after installation

Show answer and explanation

Correct answer: C

Explanation

The best answer is to use Run as administrator with local administrator credentials for the specific installation task. In Windows, administrative actions should be performed with the least privilege necessary. Elevating a single process is safer than granting a standard user account membership in the local Administrators group or routinely using the built-in Administrator account. Microsoft security guidance also supports keeping UAC enabled and minimizing the use of highly privileged accounts. On a workgroup PC, local administrator credentials can be used when elevation is needed without permanently changing the technician's account permissions.

  • A. Incorrect.

    This is not the best choice. While the built-in Administrator account can perform the installation, leaving it enabled for convenience violates security best practices. The built-in Administrator account has full privileges and bypasses some UAC protections, so it should typically remain disabled unless there is a specific administrative recovery need.

  • B. Incorrect.

    This would work technically, but it is not the best answer. Temporarily adding a user to the local Administrators group grants broad administrative privileges beyond what is needed for a single task. Best practice is to use least privilege and elevate only the specific process that requires administrator rights rather than changing group membership.

  • C. Correct.

    This is correct. Using Run as administrator and supplying local administrator credentials elevates only the installer process, allowing the application to be installed without granting the technician ongoing administrative rights. This aligns with least privilege and standard Windows administrative best practices for occasional elevated tasks.

  • D. Incorrect.

    This is incorrect. Disabling UAC reduces system security and does not follow best practices. UAC is designed to help prevent unauthorized system-wide changes by requiring consent or credentials for elevated actions. Temporarily turning it off to simplify installation creates unnecessary risk and is not the preferred administrative method.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam