hardMultiple Choice
220-1202 Practice Question: A server administrator needs to grant a junior…
A server administrator needs to grant a junior technician the ability to reset user passwords on a Windows Server 2019 domain controller, but without giving them full administrative rights. Which administrative tool should be used to delegate this specific permission?
⚠ Common exam trap
The Delegation of Control Wizard allows granular permissions, whereas built-in groups like Account Operators grant overly broad rights, violating the principle of least privilege.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Active Directory Users and Computers and use the Delegation of Control Wizard.
The Delegation of Control Wizard in Active Directory Users and Computers is the correct tool because it allows an administrator to grant specific permissions, such as resetting user passwords, to a non-administrative user without granting full administrative rights. This wizard modifies the ACL on the selected organizational unit (OU) or container, enabling granular control over tasks like password resets while preserving security boundaries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Local Security Policy to assign the 'Reset passwords' user right.
Why it's wrong here
Local Security Policy applies only to the local machine's accounts, not domain users on a domain controller. It is tempting because a 'Reset passwords' right does exist in security policy, but domain delegation needs the Delegation of Control Wizard to grant that permission on the relevant OU.
- ✓
Active Directory Users and Computers and use the Delegation of Control Wizard.
Why this is correct
The Delegation of Control Wizard in Active Directory Users and Computers assigns granular permissions, such as Reset password, on a specific OU without granting full Domain Admin rights. This satisfies the least-privilege requirement for the junior technician.
- ✗
Group Policy Management Console to create a policy that allows password resets.
Why it's wrong here
Group Policy configures settings and security options across objects; it does not delegate individual AD permissions such as password reset on specific users. It is tempting because GPOs do manage account policies, but delegation requires the Delegation of Control Wizard, which assigns granular rights on an OU.
- ✗
Computer Management to add the technician to the 'Account Operators' group.
Why it's wrong here
Computer Management is a local console and cannot modify domain groups; Account Operators also grants far broader rights than password reset alone. It is tempting because Account Operators can reset passwords, but the tool is wrong and the role exceeds the least-privilege requirement, unlike OU delegation.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.