220-1102 exam dumps

220-1102 practice question 379 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 379

Single answerRun as administrator vs. standard user

A help desk technician is assisting a user who needs to update settings in a legacy Windows application installed on a company laptop. The user reports that the application opens normally, but when trying to save changes, an "Access denied" error appears. The user can still use the application for normal day-to-day tasks. Company policy requires users to operate with standard accounts whenever possible and to use elevated privileges only when necessary. What is the BEST action for the technician to recommend?

  1. A

    Change the user's account type to Administrator so the application can save settings every time it runs

  2. B

    Right-click the application and choose "Run as administrator" only when the user needs to perform the settings change

  3. C

    Disable User Account Control so the application can write changes without prompting

  4. D

    Have the user sign in with the local Administrator account whenever they use the application

Show answer and explanation

Correct answer: B

Explanation

The best answer is to run the application as administrator only when the user is performing the task that requires elevated privileges. This follows the security best practice of least privilege, which is emphasized in Windows administration and A+ Core 2 objectives. Standard users should perform regular daily work without administrative rights, and elevation should be limited to specific tasks that require it. Microsoft documentation on User Account Control and standard versus administrator accounts supports this model: UAC helps separate standard user activity from administrative actions, reducing the risk of malware installation and unintended configuration changes. Making the user a permanent administrator, disabling UAC, or routinely using the built-in/local Administrator account are all less secure approaches and are not appropriate when only occasional elevation is needed.

  • A. Incorrect.

    This is incorrect because permanently changing the user to an Administrator violates the principle of least privilege. The scenario states the user can perform normal tasks without elevated rights, so granting full administrative access all the time would create unnecessary security risk.

  • B. Correct.

    This is correct because running the application with elevation only when performing the administrative task follows best practice. In Windows, some tasks such as writing to protected locations or changing system-wide settings require administrative privileges, while standard use of the application may not. Using "Run as administrator" only when needed minimizes exposure and aligns with company policy.

  • C. Incorrect.

    This is incorrect because disabling User Account Control reduces a key Windows security feature designed to help prevent unauthorized system changes. It is not an appropriate fix for an application that occasionally requires elevated privileges. The better approach is targeted elevation for the specific task.

  • D. Incorrect.

    This is incorrect because using the local Administrator account for routine application access is excessive and less secure. It also weakens accountability and increases the chance of unintended system-wide changes. Best practice is to keep users on standard accounts and elevate only the necessary process when required.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam