220-1102 exam dumps

220-1102 practice question 493 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 493

Single answerChange default administrator's user account/password

A small business uses standalone Windows 10 Pro PCs in a front-office area. During a basic security review, a technician discovers that the built-in local Administrator account is still enabled on several systems and is using the same weak password that was set during initial deployment. The office manager wants the fastest remediation that also improves security without affecting employees' standard user accounts. Which action should the technician take FIRST on each affected PC?

  1. A

    Sign in with an existing administrative account and change the built-in Administrator account to a strong, unique password

  2. B

    Delete the built-in Administrator account and create a new local admin account with the same name

  3. C

    Convert all standard user accounts to administrators so users can manage their own passwords

  4. D

    Run System Restore to revert each PC to a point before the weak password was applied

Show answer and explanation

Correct answer: A

Explanation

The best first step is to change the built-in local Administrator account to a strong, unique password on each affected standalone PC. This directly remediates the exposed credential while minimizing impact on standard users. In Windows security best practice, privileged accounts should use strong passwords, should not share the same password across devices, and should be limited in use. On standalone systems, this is commonly performed through Computer Management > Local Users and Groups or equivalent administrative tools/commands. Microsoft security guidance also supports least privilege and protecting local administrator credentials; in managed environments, technologies such as Microsoft Local Administrator Password Solution (LAPS) can automate unique local admin passwords, but for standalone PCs the immediate practical fix is to manually change the built-in Administrator password.

  • A. Correct.

    Correct. On a standalone Windows PC, the built-in local Administrator account cannot be removed in normal administration, but its password should be changed immediately if it is weak or shared. Using a different administrative account to sign in and set a strong, unique password for the built-in Administrator account is the fastest direct remediation. This addresses the identified risk without changing employee account types or disrupting normal work.

  • B. Incorrect.

    Incorrect. The built-in Administrator account is a default local account in Windows and is not handled like a normal user account for routine deletion and recreation. Attempting to replace it with another account of the same name does not properly address the security issue and can create management and support problems. The correct action is to change the password, and in many environments also disable or rename the account afterward if policy allows.

  • C. Incorrect.

    Incorrect. Giving standard users administrative privileges increases risk and violates least-privilege best practices. It does not solve the problem of the weak password on the built-in Administrator account. A user might choose this because it seems to spread password management responsibility, but it actually weakens security significantly.

  • D. Incorrect.

    Incorrect. System Restore is intended to roll back system files, settings, drivers, and certain installed applications to an earlier state. It is not an appropriate tool for remediating a known weak local administrator password across multiple PCs. In many cases, restoring to an older point could reintroduce other issues and would not be a reliable or efficient security fix.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam