mediumMultiple Choice
How to Set Up a Windows 10 Kiosk Machine Using Assigned Access
A technician is configuring a new Windows 10 kiosk computer that will run a single application for public use. They need to prevent users from accessing the desktop, taskbar, or other system functions. Which Windows security feature should be used?
Quick Answer
The answer is Assigned Access, also known as Kiosk Mode. This Windows security feature locks down the device to run only a single application for public use, preventing users from accessing the desktop, taskbar, or any other system functions by creating a restricted user account that boots directly into the designated app. On the CompTIA A+ Core 2 220-1202 exam, this scenario tests your understanding of Windows lockdown features for public-facing devices—a common trap is confusing Assigned Access with User Account Control or BitLocker, which handle permissions and encryption, not app restriction. Remember that Assigned Access is specifically for single-app kiosk setups, while a multi-app kiosk uses Shell Launcher. A helpful memory tip: think “Assigned Access = One App, No Escape.”
⚠ Common exam trap
A common misconception is that UAC or Software Restriction Policies can provide a full kiosk lockdown, but these features lack the ability to hide the desktop and taskbar or prevent users from launching other applications via keyboard shortcuts or the Start menu.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assigned Access (Kiosk Mode)
Assigned Access (Kiosk Mode) is the correct feature because it locks down the Windows 10 device to run only a single Universal Windows Platform (UWP) app or a classic Win32 app in full-screen mode, completely hiding the desktop, taskbar, Start menu, and other system interfaces. This is specifically designed for public-facing kiosk scenarios where users must not be able to exit the application or access any other system functions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
User Account Control (UAC) set to highest level
Why it's wrong here
UAC prompts for elevation on administrative actions; it does not remove the desktop, taskbar or Start menu, so users retain full shell access. UAC is intended to gate privilege escalation on standard workstations, not to constrain an interactive session to one application. Kiosk mode requires Assigned Access instead.
- ✗
Local Group Policy – Software Restriction Policies
Why it's wrong here
Software Restriction Policies control which executables may run; they do not hide or disable the desktop, taskbar or system menus, so users can still navigate Windows freely. SRP suits blocking unauthorised binaries in managed environments. Assigned Access is the feature that replaces the shell with one application.
- ✗
Windows Defender Application Guard
Why it's wrong here
Application Guard isolates untrusted websites and documents inside a hardware-based Hyper-V container; it does not restrict the interactive shell, so the desktop and taskbar remain reachable. It suits protecting browsing in untrusted-content scenarios, not locking a device to a single application. Assigned Access provides that shell restriction.
- ✓
Assigned Access (Kiosk Mode)
Why this is correct
Assigned Access locks a Windows 10 account to a single Universal Windows Platform app, hiding the desktop, taskbar, and system functions from public users. This satisfies the kiosk requirement by restricting the session to one application.
Go deeper
Related to this question
About these practice questions
This 220-1202 question is part of Courseiva's 687-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on 220-1202
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A technician is configuring a Windows 10 kiosk machine that will run a single web application in full-screen mode. The machine must not allow users to access the desktop, taskbar, or other apps. Which Windows security feature should be used to accomplish this?
medium- A.Local Group Policy to hide the taskbar.
- B.User Account Control set to 'Always notify.'
- C.Windows Defender Application Guard
- ✓ D.Assigned Access (Kiosk Mode)
Why D: Assigned Access (Kiosk Mode) is the correct Windows security feature because it locks down the device to run a single Universal Windows Platform (UWP) app or a web browser in full-screen mode, preventing users from accessing the desktop, taskbar, or other applications. This feature is specifically designed for kiosk scenarios and enforces a restricted user experience by configuring a local or domain user account to launch only the designated app upon sign-in.
Variation 2. A technician is configuring a Windows 10 kiosk system that will run a single application in a public library. The kiosk must automatically log on and start the app without any user interaction. Which security setting combination is required?
medium- A.Enable 'Sticky Keys' and configure the 'Ease of Access' settings
- ✓ B.Configure 'Automatic logon' in the registry and enable 'Assigned Access' for the kiosk account
- C.Set the 'Shutdown: Allow system to be shut down without having to log on' policy
- D.Enable 'User Account Control: Run all administrators in Admin Approval Mode'
Why B: Configuring 'Automatic logon' in the registry (via the WinLogon key) allows the kiosk to boot directly to the desktop without user interaction, while enabling 'Assigned Access' restricts the kiosk account to running only a single specified Universal Windows Platform (UWP) app, preventing access to the rest of the system. This combination meets the requirement for an unattended, single-application kiosk in a public library.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.