mediumMultiple Choice
220-1202 Practice Question: A technician is configuring a new employee's…
A technician is configuring a new employee's laptop and needs to ensure that only approved applications can run. The company wants to prevent users from installing unauthorized software. Which security control should be implemented?
⚠ Common exam trap
CompTIA expects you to recognize that while Standard User accounts limit some installations, AppLocker is the specific control for application whitelisting. The common pitfall is assuming user permissions alone can block all unauthorized software.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an application whitelist using AppLocker.
AppLocker is a Windows security feature that allows administrators to create rules that explicitly permit only approved applications to run, effectively blocking all others. This is the correct control for preventing unauthorized software installation because it enforces an application whitelist at the kernel level, overriding user permissions. Standard User accounts or antivirus alone cannot prevent execution of approved-but-unauthorized binaries, making AppLocker the precise solution for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Windows Defender real-time protection.
Why it's wrong here
Antivirus detects known malware but does not prevent installation of unauthorized legitimate software.
- ✗
Set the user account as a Standard User.
Why it's wrong here
Standard User rights limit installation to some extent but can be bypassed; it does not block all unauthorized apps.
- ✓
Configure an application whitelist using AppLocker.
Why this is correct
AppLocker enforces a whitelist, allowing only specified applications to run, directly meeting the requirement.
- ✗
Disable the Windows Store.
Why it's wrong here
Disabling the Store only blocks one source; users could still install from other locations.
Go deeper
Related to this question
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.