220-1102 exam dumps

220-1102 practice question 490 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 490

Single answerUse failed attempts lockout

A small office uses Windows 11 Pro PCs joined to a local workgroup. Several employees share the same reception computer during the day. The office manager is concerned that someone could repeatedly guess the local Administrator password after hours. She wants the PC to automatically block further sign-in attempts after several failed passwords, but she does not want to remove the account or require third-party software. Which action should the technician take to best meet this requirement?

  1. A

    Configure an account lockout threshold in the Local Security Policy for the PC

  2. B

    Enable BitLocker on the system drive

  3. C

    Rename the Administrator account and leave sign-in attempts unlimited

  4. D

    Set the screen saver to require a password after 5 minutes

Show answer and explanation

Correct answer: A

Explanation

The best solution is to configure a failed-attempts lockout using Windows Account Lockout Policy in Local Security Policy on the standalone/workgroup PC. This is the built-in Windows method for limiting password-guessing attempts against local accounts. Relevant settings typically include Account lockout threshold, which determines how many failed attempts trigger lockout; Account lockout duration, which determines how long the account remains locked; and Reset account lockout counter after, which defines when the failed-attempt count returns to zero. This aligns with common security best practices and Microsoft guidance for account policies in Windows. The other options improve security in different ways, but they do not specifically implement a failed attempts lockout.

  • A. Correct.

    Correct. In Windows Professional editions, a technician can use Local Security Policy to configure Account Lockout Policy settings such as Account lockout threshold, Account lockout duration, and Reset account lockout counter after. This directly addresses the requirement to stop repeated password-guessing attempts on a local account after a defined number of failures.

  • B. Incorrect.

    Incorrect. BitLocker protects data at rest by encrypting the drive, which is useful if the device is lost or stolen. However, it does not enforce a failed-attempt lockout for Windows sign-in after the OS is running, so it does not solve the manager's stated problem.

  • C. Incorrect.

    Incorrect. Renaming the Administrator account can reduce exposure to simple attacks that target the default account name, but it does not limit repeated failed sign-in attempts by itself. The requirement is specifically to block further attempts after several failures, which requires an account lockout policy.

  • D. Incorrect.

    Incorrect. Requiring a password after screen saver activation helps protect an unattended session, but it does not control how many failed sign-in attempts are allowed. This is a physical/session security measure, not a failed-attempt lockout control.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam