easyMultiple ChoiceObjective-mapped
220-1202 Practice Question: A technician is configuring a new Windows 11…
A technician is configuring a new Windows 11 workstation for a user who frequently downloads free software. To reduce the risk of malware infections from bundled applications, which security setting should be enabled?
⚠ Common exam trap
CompTIA A+ exams often test the distinction between malware prevention (UAC prompts) and other security features like isolation (Application Guard) or encryption (BitLocker), leading candidates to choose a more advanced-sounding option that does not address the specific threat of bundled software installations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set User Account Control to always notify.
User Account Control (UAC) set to 'Always notify' is the correct choice because it prompts the user for consent or credentials whenever an application (including bundled installers) attempts to make system-level changes. This gives the user a chance to review and block unauthorized installations, directly reducing the risk of malware from bundled freeware. The other options address different security concerns: Application Guard isolates browser sessions, Firewall controls network traffic, and BitLocker encrypts data at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Windows Defender Application Guard.
Why it's wrong here
Windows Defender Application Guard (WDAG) is a security feature designed to isolate untrusted websites and PDF documents within a virtualized container, protecting the host system from potential browser-based exploits. While it enhances security against web threats by preventing malicious code from reaching the main OS, it does not directly intervene or prevent the installation of bundled software that a user might initiate from a downloaded executable. Its scope is limited to browser and document isolation, not general application installation control.
- ✓
Set User Account Control to always notify.
Why this is correct
Setting User Account Control (UAC) to "Always notify" ensures that the user is prompted for explicit consent before any program makes changes that require administrative privileges, including software installations. This prompt provides a crucial opportunity to review and reject installations, effectively preventing unwanted bundled software from being installed alongside a desired application. It acts as a critical gatekeeper for system-wide changes, empowering the user to control what gets installed.
- ✗
Turn on Windows Firewall with advanced logging.
Why it's wrong here
Windows Firewall primarily functions to control inbound and outbound network traffic, blocking unauthorized connections and protecting the system from network-based attacks. While advanced logging can provide detailed information about network activity, the firewall itself does not prevent the local installation of software executables initiated by a user. It operates at the network layer, not at the application installation layer, making it ineffective against bundled software installs.
- ✗
Enable BitLocker drive encryption.
Why it's wrong here
BitLocker drive encryption is a full-disk encryption feature designed to protect data at rest by encrypting the entire volume, making it unreadable to unauthorized users if the device is lost or stolen. Its primary purpose is data confidentiality and integrity, not the prevention of software installations or malware execution on an active system. BitLocker does not monitor or block the installation process of applications, whether bundled or standalone, as its function is post-installation data protection.
Go deeper
Related to this question
Learn chapter
Introduction to Windows Operating Systems
Key term
User Account Control
User Account Control (UAC) is a Windows security feature that prevents unauthorized changes to the operating system by prompting for permission before allowing actions that affect system settings or installed programs.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.