220-1102 exam dumps

220-1102 practice question 380 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 380

Single answerUser Account Control (UAC)

A user on a Windows 11 Pro laptop is logged in with a standard user account. They need to install a line-of-business application that writes to protected areas of the system, and they call the help desk for assistance. The technician wants to allow the installation without giving the user permanent administrative rights or disabling security features across the PC. Which action is the BEST choice?

  1. A

    Temporarily add the user to the local Administrators group, have them install the application, and leave the account as-is unless problems occur

  2. B

    Disable User Account Control (UAC) from Control Panel, restart the PC, complete the installation, and then turn UAC back on later

  3. C

    Sign in with an administrator account or provide administrator credentials when prompted by UAC so the installer runs with elevated permissions

  4. D

    Change the application's shortcut to Run this program as an administrator so the standard user can install it without additional credentials

Show answer and explanation

Correct answer: C

Explanation

The best answer is to use UAC as intended: authorize the installation with administrator credentials only for that task. In Windows, UAC helps limit the use of full administrative privileges and prompts for consent or credentials when software attempts to make changes that affect the system, such as writing to protected directories or modifying system-wide settings. For a standard user, the prompt requires administrator credentials; for an administrator account, it typically requires consent. This approach aligns with the principle of least privilege and common help-desk practice. By contrast, disabling UAC or making the user a local administrator weakens security and increases risk. Microsoft documentation and Windows security best practices consistently recommend keeping UAC enabled and using elevation only when required for administrative actions.

  • A. Incorrect.

    Incorrect. Temporarily adding the user to the local Administrators group grants broader privileges than necessary and increases the risk of unintended system changes. It also creates the possibility that the account is left with elevated rights. Best practice is to use least privilege and elevate only the specific task that requires administrative approval.

  • B. Incorrect.

    Incorrect. Disabling UAC reduces an important security control that helps prevent unauthorized or unintended system-level changes. Although this might allow the installation to proceed, it is not the best practice for a routine software install. Microsoft guidance generally recommends leaving UAC enabled and approving elevation only when needed.

  • C. Correct.

    Correct. UAC is designed to allow administrative tasks to be performed without making the user a permanent administrator. On a standard user account, UAC presents a credential prompt, allowing an administrator to authorize the specific action. This follows least-privilege security principles and is the safest, most appropriate way to complete the installation.

  • D. Incorrect.

    Incorrect. Marking an application to always run as administrator does not let a standard user bypass UAC. A standard user still cannot elevate without administrator credentials. This setting can also cause repeated elevation prompts and is not the proper method for granting temporary installation rights.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam