220-1102 exam dumps

220-1102 practice question 555 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 555

Single answerTrusted sources

A user needs to install a line-of-business Windows application that your company packages internally. When the user launches the installer, Windows displays a warning that the publisher cannot be verified. You confirm the installer is legitimate and signed with the company’s internal code-signing certificate. The installation must proceed without disabling security features for all software on the PC. Which action should the technician take?

  1. A

    Import the company’s code-signing certificate into the Trusted Publishers store on the user’s computer

  2. B

    Disable User Account Control (UAC) before running the installer, then re-enable it afterward

  3. C

    Add the installer’s folder to the browser’s trusted sites list

  4. D

    Change the file extension from .exe to .msi so Windows treats it as a trusted installer

Show answer and explanation

Correct answer: A

Explanation

This question tests practical use of trusted sources in Windows. In a managed environment, internally developed or repackaged applications are often signed with an enterprise code-signing certificate. If Windows cannot verify the publisher, the proper fix is to trust the signing certificate rather than disable security controls. Best practice is to deploy the organization’s certificate through centralized management, such as Group Policy, so devices trust approved publishers consistently. Microsoft documentation on certificate stores and code signing supports using Trusted Publishers for trusted software publishers, while UAC and browser security zones serve different purposes and should not be used as substitutes for certificate-based trust.

  • A. Correct.

    Correct. If the installer is legitimately signed with the organization’s internal code-signing certificate, placing that certificate in the appropriate trust store allows Windows to recognize the publisher as trusted. For code-signed software, the Trusted Publishers store is used to trust software publishers, and the certificate chain may also need to chain to a trusted root. This approach solves the warning without broadly weakening system protections.

  • B. Incorrect.

    Incorrect. UAC controls elevation prompts and administrative approval, but it does not establish trust for an unknown or untrusted software publisher. Disabling UAC reduces security and does not address the certificate trust issue that caused the publisher warning.

  • C. Incorrect.

    Incorrect. Trusted Sites is an Internet Explorer/Windows security zone setting related to web content and browser-related trust behavior, not to trusting the digital signature of a local Windows installer. A candidate might choose this because of the word 'trusted,' but it applies to websites, not signed executables.

  • D. Incorrect.

    Incorrect. Changing a file extension does not make software trusted or signed. Windows validates digital signatures and certificate trust independently of the visible filename extension. Also, renaming an executable to a different package type would usually break the installation rather than solve the publisher verification problem.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam