220-1102 exam dumps

220-1102 practice question 368 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 368

Single answerPower user

A graphic designer uses a Windows workstation to run CAD software and frequently installs printer drivers, changes advanced network settings for testing, and troubleshoots application compatibility issues. The user asks to be added to the local Administrators group so they can work without opening help desk tickets. The company follows least-privilege security practices and wants to reduce the risk of malware or accidental system-wide changes. Which action is the BEST way to meet the user's needs while maintaining security?

  1. A

    Add the user to the local Administrators group permanently so they can manage any system setting without interruption

  2. B

    Add the user to the local Power Users group so they can install software and make system-wide changes without full administrative rights

  3. C

    Keep the user as a standard user and provide elevation only when required through administrative credentials or approved support processes

  4. D

    Disable User Account Control (UAC) for the user so trusted applications can run with elevated permissions automatically

Show answer and explanation

Correct answer: C

Explanation

The best answer is to keep the user as a standard user and use elevation only when required. For A+ Core 2, the key concept is applying least privilege rather than granting broad local administrative rights for convenience. The term "Power Users" is important historically, but on modern Windows systems it is largely a legacy group and should not be treated as a secure or recommended middle-tier administrative solution. Microsoft security guidance and Windows administrative best practices emphasize using standard user accounts for daily work, UAC for elevation prompts, and controlled administrative access only when necessary. This approach limits the attack surface, reduces accidental system changes, and still supports legitimate business needs through approved elevation or support procedures.

  • A. Incorrect.

    This is incorrect because permanently adding the user to the local Administrators group grants broad control over the system, including installing software, modifying security settings, and managing other accounts. That level of access conflicts with least-privilege practices and increases the impact of phishing, malware, or user error.

  • B. Incorrect.

    This is incorrect because the Power Users group is a legacy Windows group and does not provide the practical delegated administrative role many people assume it does on modern versions of Windows. On current Windows systems, it is not the recommended way to allow software installation or broad configuration changes, and relying on it reflects an outdated permissions model.

  • C. Correct.

    This is correct because it follows the principle of least privilege while still allowing administrative tasks to be completed when necessary. In Windows, standard users can perform normal daily work, and administrative actions can be approved through UAC using admin credentials or handled through an authorized support workflow. This reduces persistent risk while still supporting occasional elevated tasks.

  • D. Incorrect.

    This is incorrect because disabling UAC weakens an important Windows security control. UAC helps separate standard-user activity from administrative actions and prompts for consent or credentials when elevation is needed. Turning it off does not create a proper role for a power user; it simply reduces security and makes silent elevation easier for malicious software.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam