220-1102 exam dumps

220-1102 practice question 89 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 89

Single answerLocal User and Groups (lusrmgr.msc)

A technician is preparing a shared Windows 10 Pro workstation for a temporary employee who needs to run a line-of-business application and save files to a department share. Company policy requires the user to have the fewest privileges necessary and prevents the user from making system-wide changes. The computer is not joined to a domain. Which action in Local Users and Groups (lusrmgr.msc) best meets this requirement?

  1. A

    Create a local user account for the employee and add the account to the Users group only.

  2. B

    Create a local user account for the employee and add the account to the Administrators group.

  3. C

    Enable the built-in Guest account and have the employee sign in with that account.

  4. D

    Create a local user account for the employee and add the account to the Power Users group.

Show answer and explanation

Correct answer: A

Explanation

The best answer is to create a unique local account and keep it in the Users group. In lusrmgr.msc, this supports least-privilege administration, which is a core security best practice and aligns with how Windows local groups are intended to be used. The Administrators group would provide unnecessary elevated rights. The Guest account is disabled by default and is inappropriate when accountability and traceability matter. The Power Users group is a legacy compatibility group and is generally not used for assigning modern workstation permissions. Microsoft documentation and Windows security best practices consistently recommend assigning only the permissions needed for the user's role and using standard user accounts whenever administrative rights are not required.

  • A. Correct.

    Correct. Creating a standard local user and leaving it in the Users group follows the principle of least privilege. Members of the Users group can sign in and run permitted applications but cannot perform most administrative tasks or make protected system-wide changes. This is the appropriate choice for a temporary employee who only needs normal workstation access.

  • B. Incorrect.

    Incorrect. The Administrators group grants elevated privileges, including installing software, changing system settings, and managing other accounts. That exceeds the stated business requirement and violates least-privilege best practices. A candidate might choose this because the application may need to run, but the scenario does not indicate administrative rights are required.

  • C. Incorrect.

    Incorrect. The built-in Guest account is intended for very limited, temporary access and is disabled by default on modern Windows systems for security reasons. It is not the best practice for assigning an identifiable employee account, and it provides poor accountability because it is a shared generic account.

  • D. Incorrect.

    Incorrect. Power Users is a legacy group retained mainly for backward compatibility and is not the recommended way to grant access on modern Windows systems. It can provide more privileges than necessary and does not align with current best practice for standard user access. Someone might pick this option based on outdated knowledge that it is a middle ground between Users and Administrators.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam