220-1102 exam dumps

220-1102 practice question 91 of 828

A+ Core 2. Associate level, CompTIA. Free question with the correct answer and a full explanation.

220-1102 Question 91

Single answerGroup Policy Editor (gpedit.msc)

A technician is configuring a shared Windows 10 Pro workstation in a training room. Users have local standard accounts, and management wants to prevent them from opening Control Panel and the Settings app, while still allowing administrators to manage the PC normally. The computer is not joined to a domain. Which action in Local Group Policy Editor (gpedit.msc) best meets this requirement?

  1. A

    Enable the policy "Prohibit access to Control Panel and PC settings" under User Configuration > Administrative Templates > Control Panel

  2. B

    Enable the policy "Prevent access to the command prompt" under User Configuration > Administrative Templates > System

  3. C

    Enable the policy "Hide specified Control Panel items" under Computer Configuration > Administrative Templates > Control Panel

  4. D

    Enable the policy "Remove Run menu from Start Menu" under User Configuration > Administrative Templates > Start Menu and Taskbar

Show answer and explanation

Correct answer: A

Explanation

The best answer is to enable "Prohibit access to Control Panel and PC settings" in User Configuration > Administrative Templates > Control Panel. This is the most direct and supported Local Group Policy setting for preventing users from opening those management interfaces on Windows Pro editions that include gpedit.msc. Because the scenario specifies a standalone PC and a requirement focused on user behavior, a user-based local policy is more appropriate than unrelated system restrictions or partial UI changes. Microsoft documents this Administrative Template policy as the standard method to block access to Control Panel and Settings for targeted users. In real-world support environments, this is commonly used on kiosks, lab systems, training-room PCs, and other shared workstations.

  • A. Correct.

    Correct. In Local Group Policy Editor, the policy "Prohibit access to Control Panel and PC settings" is the direct setting used to block users from opening both Control Panel and the Settings app. Because this is a User Configuration policy, it applies to user accounts rather than the whole computer, which aligns with the goal of restricting standard users while allowing administrators to use their own accounts normally. On a standalone Windows Pro system, gpedit.msc is the appropriate tool for this type of local user restriction.

  • B. Incorrect.

    Incorrect. Blocking Command Prompt does not prevent access to Control Panel or the Settings app. This option is plausible because technicians often use System policies to restrict user capabilities, but it addresses a different administrative concern.

  • C. Incorrect.

    Incorrect. "Hide specified Control Panel items" only hides selected applets and does not fully block access to Control Panel and Settings. It is also not the best match for the stated requirement, which is to prohibit access entirely. A candidate might choose this if they confuse hiding items with fully denying access.

  • D. Incorrect.

    Incorrect. Removing the Run menu may reduce one method of launching tools, but users could still access Control Panel or Settings through other paths, such as the Start menu, search, or file associations. This is an interface change, not a direct access restriction.

Timed practice exam

Take a 220-1102 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam