easyMultiple Choice
220-1202 Practice Question: A small business owner wants to ensure that only…
A small business owner wants to ensure that only authorized USB storage devices can be used on company laptops running Windows 10 Pro. They have a list of approved device hardware IDs. Which security policy should be configured to enforce this restriction?
⚠ Common exam trap
CompTIA often tests the distinction between access control policies (like Removable Storage Access) and device installation restriction policies, leading candidates to confuse permission-based controls with hardware-based whitelisting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the 'Allow installation of devices that match any of these device IDs' policy under Device Installation Restrictions
The 'Allow installation of devices that match any of these device IDs' policy under Device Installation Restrictions allows an administrator to specify a whitelist of approved hardware IDs. When configured, only USB storage devices whose hardware IDs match the list will be installed, effectively blocking all unauthorized devices. This directly enforces the requirement to restrict USB storage to approved devices only.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the 'Removable Storage Access' policy under Windows Components
Why it's wrong here
Removable Storage Access policies deny read or write classes such as USB, but cannot allow specific approved hardware IDs. It tempts because it targets removable storage directly, and would be correct when blocking all USB storage outright rather than permitting an approved list.
- ✗
Configure the 'Devices: Restrict CD-ROM access to locally logged-on user only' policy
Why it's wrong here
This policy only restricts CD-ROM and DVD access to the locally logged-on user; it does not evaluate USB hardware IDs or block unauthorised storage. It is tempting because it addresses removable media access, and would be correct when limiting optical drive sharing between concurrent local and remote sessions.
- ✗
Set the 'Deny all devices' policy under Device Installation Restrictions
Why it's wrong here
Deny all devices blocks every device installation, including the approved USB storage, so no allow-list can operate. It is tempting as the strictest lockdown, and would be correct in a high-security environment where no removable storage is ever permitted.
- ✓
Configure the 'Allow installation of devices that match any of these device IDs' policy under Device Installation Restrictions
Why this is correct
Device Installation Restrictions with the allow-list policy permits only hardware IDs on the approved list to install, blocking all other USB storage. This enforces the owner's allow-list requirement directly, since the policy evaluates device IDs at installation rather than blocking the USB class wholesale.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.