Courseiva
easyMultiple Choice

220-1202 Practice Question: A small business owner wants to ensure that only…

A small business owner wants to ensure that only authorized USB storage devices can be used on company laptops running Windows 10 Pro. They have a list of approved device hardware IDs. Which security policy should be configured to enforce this restriction?

⚠ Common exam trap

CompTIA often tests the distinction between access control policies (like Removable Storage Access) and device installation restriction policies, leading candidates to confuse permission-based controls with hardware-based whitelisting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the 'Allow installation of devices that match any of these device IDs' policy under Device Installation Restrictions

The 'Allow installation of devices that match any of these device IDs' policy under Device Installation Restrictions allows an administrator to specify a whitelist of approved hardware IDs. When configured, only USB storage devices whose hardware IDs match the list will be installed, effectively blocking all unauthorized devices. This directly enforces the requirement to restrict USB storage to approved devices only.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable the 'Removable Storage Access' policy under Windows Components

    Why it's wrong here

    Removable Storage Access policies deny read or write classes such as USB, but cannot allow specific approved hardware IDs. It tempts because it targets removable storage directly, and would be correct when blocking all USB storage outright rather than permitting an approved list.

  • ✗

    Configure the 'Devices: Restrict CD-ROM access to locally logged-on user only' policy

    Why it's wrong here

    This policy only restricts CD-ROM and DVD access to the locally logged-on user; it does not evaluate USB hardware IDs or block unauthorised storage. It is tempting because it addresses removable media access, and would be correct when limiting optical drive sharing between concurrent local and remote sessions.

  • ✗

    Set the 'Deny all devices' policy under Device Installation Restrictions

    Why it's wrong here

    Deny all devices blocks every device installation, including the approved USB storage, so no allow-list can operate. It is tempting as the strictest lockdown, and would be correct in a high-security environment where no removable storage is ever permitted.

  • ✓

    Configure the 'Allow installation of devices that match any of these device IDs' policy under Device Installation Restrictions

    Why this is correct

    Device Installation Restrictions with the allow-list policy permits only hardware IDs on the approved list to install, blocking all other USB storage. This enforces the owner's allow-list requirement directly, since the policy evaluates device IDs at installation rather than blocking the USB class wholesale.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.