220-1102 exam dumps

220-1102 practice question 390 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 390

Single answerSelecting security groups

A technician is setting up access for a new group of interns in a Windows domain environment. The interns need to read files in a shared training folder, but they must not be able to modify or delete any files. The company also wants administration to remain simple as interns are hired and leave throughout the year. Which action should the technician take FIRST to follow best practices when selecting security groups?

  1. A

    Add each intern's user account directly to the NTFS permissions on the training folder with Read access

  2. B

    Create a security group for interns, add the interns to that group, and assign the group Read permissions to the folder

  3. C

    Create a distribution group for interns and assign the group Read permissions to the folder

  4. D

    Add all interns to the local Administrators group so they can access the folder without permission issues

Show answer and explanation

Correct answer: B

Explanation

The best answer is to use a security group and assign that group the minimum required permissions. In Windows environments, security groups are used to control access to resources such as shared folders, printers, and NTFS-protected files. This approach supports scalability, easier onboarding and offboarding, and the principle of least privilege. Distribution groups are used for email and cannot be relied on for resource permission assignments. CompTIA A+ Core 2 objectives emphasize proper account management, permission assignment, and selecting the appropriate security settings for users and groups. Microsoft best practices also recommend assigning permissions to groups rather than directly to user accounts whenever possible.

  • A. Incorrect.

    This is not the best first step. While directly assigning NTFS permissions to individual user accounts can work, it does not scale well and becomes difficult to manage as interns join or leave. Best practice in Windows environments is to assign permissions to security groups rather than individual users whenever possible.

  • B. Correct.

    This is correct. A security group is designed to simplify permission management. By placing intern accounts into a dedicated security group and assigning Read access to that group, the technician follows the principle of least privilege and makes future administration easier. When interns change, the technician only needs to update group membership instead of editing folder permissions repeatedly.

  • C. Incorrect.

    This is incorrect because distribution groups are primarily used for email distribution and are not intended for assigning permissions to resources such as NTFS folders. A common misconception is that any group can be used for access control, but in Windows, security groups are specifically used for permissions.

  • D. Incorrect.

    This is incorrect and creates a major security risk. The local Administrators group grants elevated privileges far beyond simple folder access. This violates the principle of least privilege and could allow interns to make unauthorized system changes.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam