mediumMultiple Choice
Block Browser Extensions Using Group Policy
A small business owner wants to ensure that employees cannot install browser extensions or add-ons without administrator approval. Which method should the technician use to enforce this restriction across all company computers?
Quick Answer
The answer is to use Group Policy to disable extension installation. This is the correct method because Group Policy in Windows provides centralized administrative control over browser settings across all domain-joined computers, allowing IT to enforce restrictions such as blocking browser extensions without requiring manual configuration on each machine. On the CompTIA A+ Core 2 220-1202 exam, this question tests your understanding of enterprise-level security management versus local settings; a common trap is choosing a local security policy or registry edit, which lacks the scalability of Group Policy for an entire organization. Remember that Group Policy is the go-to tool for domain-wide browser controls, while local policies only affect a single computer. A helpful memory tip: think of Group Policy as the "group boss" that tells every browser in the company, "No add-ons without my say-so."
⚠ Common exam trap
Many exam-takers think a firewall or manual configuration is sufficient, but the A+ exam tests the understanding that Group Policy is the only centralized, scalable method for enforcing browser restrictions in a domain environment, while firewalls operate at the network layer and cannot intercept browser-internal operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Group Policy to disable extension installation.
Group Policy (specifically the Administrative Templates for Google Chrome, Microsoft Edge, or Firefox) provides a centralized method to enforce browser settings across all domain-joined computers. By configuring the 'Block external extensions' or 'ExtensionInstallBlockList' policy, the technician can prevent users from installing extensions without administrator approval, ensuring consistent enforcement without manual intervention on each machine.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure each browser's settings manually on every computer.
Why it's wrong here
Manually configuring each browser's settings is per-machine and per-browser, so it neither scales across all company computers nor reliably prevents users reinstalling extensions. It is tempting for a small fleet, but centralised enforcement through Group Policy or browser management policy is required to block installation without administrator approval.
- ✓
Use Group Policy to disable extension installation.
Why this is correct
Group Policy centrally enforces the browser extension restriction across all domain-joined company computers, satisfying the requirement that employees cannot install extensions without administrator approval. Disabling extension installation via Computer Configuration removes users' ability to add them, unlike per-device settings that leave each machine independently configurable.
- ✗
Install a third-party firewall to block extension downloads.
Why it's wrong here
A third-party firewall filters network traffic by port, protocol or address; browser extension installation occurs locally within the browser and is not a network flow it can intercept. It is tempting because firewalls block downloads generally, but extension approval requires browser-level policy enforcement, such as administrative templates or managed extension settings.
- ✗
Set the browser to private browsing mode.
Why it's wrong here
Private browsing prevents the local browser from retaining history, cookies and form data; it does not restrict extension installation, so users could still add extensions. It is tempting as a privacy control for shared machines, but enforcing administrator approval requires policy-based extension allowlisting or blocking via Group Policy or browser management.
Go deeper
Related to this question
About these practice questions
This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1202
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A small business owner wants to ensure that employees cannot install unauthorized browser extensions on company-managed Windows 10 computers. Which method should you use to enforce this restriction?
easy- A.Enable private browsing mode in each browser
- ✓ B.Configure Group Policy to block extension installation
- C.Set the browser homepage to a company-approved site
- D.Install an ad-blocker extension
Why B: Group Policy allows administrators to centrally manage Windows settings, including browser policies. By configuring the 'Block installation of extensions' policy under Administrative Templates for each browser (e.g., Chrome, Edge), you can prevent users from installing unauthorized extensions on company-managed Windows 10 computers.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.