220-1102 exam dumps

220-1102 practice question 560 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 560

Single answerTrusted sources

A technician is preparing a Windows 11 workstation for an accounting application that uses an older ActiveX control signed by the software vendor. When users browse to the vendor's internal web portal in Internet Explorer mode through Microsoft Edge, they receive a warning that the publisher cannot be trusted and the control will not install. The vendor has provided its root certificate and confirmed it should be trusted for this application. The technician wants to allow the control to install without broadly weakening browser security for other websites. Which action should the technician take?

  1. A

    Import the vendor's root certificate into the Trusted Root Certification Authorities store on the workstation

  2. B

    Add the vendor's website to the Restricted sites zone in Internet Options

  3. C

    Disable User Account Control so signed ActiveX controls can install without prompts

  4. D

    Turn off Microsoft Defender SmartScreen for all users on the workstation

Show answer and explanation

Correct answer: A

Explanation

The key issue is publisher trust, not browser permissions or administrative prompting. In Windows, signed code is validated through the certificate chain. If the signing certificate chains to a root CA that the local computer does not trust, users will see publisher trust warnings. Importing the vendor's root certificate into the Trusted Root Certification Authorities store establishes that certificate chain as trusted, which is the appropriate way to define a trusted source in this scenario. By contrast, changing zone settings, disabling UAC, or turning off SmartScreen either fails to solve the certificate trust problem or weakens security more broadly than necessary. This aligns with Microsoft best practices for certificate-based trust management in Windows, where trust should be established through proper certificate stores rather than by disabling protective features.

  • A. Correct.

    Correct. If the vendor's signing chain depends on a root CA that is not already trusted by the system, importing the vendor's root certificate into the Trusted Root Certification Authorities store allows Windows to validate the publisher's digital signature. This addresses the trust warning at its source and is the most targeted way to establish the vendor as a trusted source for signed content.

  • B. Incorrect.

    Incorrect. The Restricted sites zone applies tighter security settings, which would make ActiveX installation less likely to succeed. A candidate might choose this option because it involves site trust configuration, but Restricted sites is used to limit permissions, not establish publisher trust.

  • C. Incorrect.

    Incorrect. User Account Control manages elevation prompts and privilege boundaries; it does not make an untrusted publisher trusted. This is a common misconception because installation prompts and trust warnings can appear together, but they serve different security purposes.

  • D. Incorrect.

    Incorrect. Microsoft Defender SmartScreen helps protect against malicious downloads and unrecognized apps. Disabling it system-wide would reduce security broadly and still does not directly fix a missing or untrusted certificate chain for the ActiveX publisher.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam