220-1102 exam dumps

220-1102 practice question 486 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 486

Single answerAccount management

A technician is onboarding a temporary accounting contractor who will use a shared Windows 11 workstation for three months. The contractor needs to run the company’s accounting application and save files to a department network share, but management does not want the user to install software, change system-wide settings, or access other employees’ files on the PC. Which account configuration is the BEST choice?

  1. A

    Create a standard user account for the contractor and grant access only to the required network share and application

  2. B

    Create a local administrator account for the contractor so the accounting application can run without permission issues

  3. C

    Have the contractor use another employee’s account so existing application and share permissions remain unchanged

  4. D

    Create a guest account for the contractor because temporary workers should use the least permanent account type

Show answer and explanation

Correct answer: A

Explanation

The best answer is to create a standard user account with only the permissions needed for the job. In account management, CompTIA A+ Core 2 emphasizes using least privilege, assigning appropriate permissions, and avoiding shared or overly privileged accounts. For a temporary contractor, the technician should create an individual account, place it in the appropriate groups if needed, and assign access only to required resources such as the accounting application and department share. Microsoft security best practices also support using standard accounts for daily work and reserving administrator privileges for administrative tasks only. This approach improves security, supports auditing, and aligns with real-world account management practices.

  • A. Correct.

    Correct. A standard user account follows the principle of least privilege, which is the recommended approach for temporary or regular users who only need to run approved applications and access specific resources. Access to the accounting application and the department network share can be granted without giving elevated rights. This meets the business need while reducing the risk of unwanted software installation, configuration changes, or access to other local data.

  • B. Incorrect.

    Incorrect. A local administrator account grants far more permissions than required, including the ability to install software, change system settings, and potentially access protected areas of the system. This conflicts directly with management’s requirement to limit the contractor’s abilities. A common misconception is that users need administrator rights just to run business applications, but properly deployed applications should run under standard user permissions.

  • C. Incorrect.

    Incorrect. Sharing accounts is a poor security practice because it removes accountability, complicates auditing, and exposes another employee’s data and access rights. It also violates common organizational security policies. Even if permissions already exist on that employee account, each user should have a unique account for authentication, authorization, and tracking.

  • D. Incorrect.

    Incorrect. The built-in Guest account is not the best solution and is typically disabled or unavailable in modern Windows environments. Even where guest-style access exists, it is too limited and not appropriate for a worker who needs ongoing access to a business application and a specific network share. Temporary status does not mean the user should use a guest account; it means the user should receive a properly scoped individual account.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam