Courseiva
hardMultiple Choice

220-1202 Practice Question: A server administrator needs to grant a junior…

A server administrator needs to grant a junior technician the ability to reset user passwords on a Windows Server 2019 domain controller, but without giving them full administrative rights. Which administrative tool should be used to delegate this specific permission?

⚠ Common exam trap

The Delegation of Control Wizard allows granular permissions, whereas built-in groups like Account Operators grant overly broad rights, violating the principle of least privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Active Directory Users and Computers and use the Delegation of Control Wizard.

The Delegation of Control Wizard in Active Directory Users and Computers is the correct tool because it allows an administrator to grant specific permissions, such as resetting user passwords, to a non-administrative user without granting full administrative rights. This wizard modifies the ACL on the selected organizational unit (OU) or container, enabling granular control over tasks like password resets while preserving security boundaries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Local Security Policy to assign the 'Reset passwords' user right.

    Why it's wrong here

    Local Security Policy applies only to the local machine's accounts, not domain users on a domain controller. It is tempting because a 'Reset passwords' right does exist in security policy, but domain delegation needs the Delegation of Control Wizard to grant that permission on the relevant OU.

  • ✓

    Active Directory Users and Computers and use the Delegation of Control Wizard.

    Why this is correct

    The Delegation of Control Wizard in Active Directory Users and Computers assigns granular permissions, such as Reset password, on a specific OU without granting full Domain Admin rights. This satisfies the least-privilege requirement for the junior technician.

  • ✗

    Group Policy Management Console to create a policy that allows password resets.

    Why it's wrong here

    Group Policy configures settings and security options across objects; it does not delegate individual AD permissions such as password reset on specific users. It is tempting because GPOs do manage account policies, but delegation requires the Delegation of Control Wizard, which assigns granular rights on an OU.

  • ✗

    Computer Management to add the technician to the 'Account Operators' group.

    Why it's wrong here

    Computer Management is a local console and cannot modify domain groups; Account Operators also grants far broader rights than password reset alone. It is tempting because Account Operators can reset passwords, but the tool is wrong and the role exceeds the least-privilege requirement, unlike OU delegation.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.