Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company policy requires that all laptops be configured to lock and require a password after 15 minutes of inactivity. Which Windows feature should the technician configure to enforce this policy?

⚠ Common exam trap

Many exam-takers confuse Power & sleep settings with screen saver lock behavior, assuming that setting the display to turn off after 15 minutes will also lock the workstation, but sleep mode does not inherently require a password on resume unless the 'Require sign-in on wakeup' setting is also enabled, which is a separate configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Screen saver with password protection enabled

The screen saver with password protection enabled is the correct feature because it directly meets the requirement to lock the workstation after a set period of inactivity. When configured, the screen saver activates after 15 minutes and, with the 'On resume, display logon screen' setting, forces the user to re-enter their password, effectively locking the session. This is the traditional Windows method for enforcing idle-time lockout policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Screen saver with password protection enabled

    Why this is correct

    Configuring the screen saver to start after a defined idle period and enabling the 'On resume, display logon screen' checkbox (or password protection) causes the workstation to enter a locked state; the Secure Desktop then displays the lock screen, requiring the user's password, PIN, or other Windows Hello credential to dismiss the screen saver and regain access. Because this is a local session lock triggered purely by inactivity, it directly satisfies the company's requirement to lock the laptop after a period of non-use.

  • ✗

    Windows Defender Firewall

    Why it's wrong here

    Windows Defender Firewall is a host-based firewall that filters inbound and outbound network traffic according to configured rules, protecting against network-based attacks. It does not monitor console idle time, manage the user session, or invoke any form of workstation lock; its security boundary is the network interface, not the interactive desktop. Enabling or disabling this feature has no effect on whether a laptop locks after inactivity.

  • ✗

    Power & sleep settings

    Why it's wrong here

    Power & sleep settings control when the display turns off and when the system enters sleep/hibernate to conserve energy, not when the user session is locked. While Windows may offer a 'Require sign-in on wakeup' option, that behavior is configured separately under Accounts > Sign-in options and can be disabled; reliance on power settings alone leaves the laptop unlocked if the system merely wakes from an idle display on a device with no password prompt. Therefore, power management is not a dependable lockdown mechanism and must be paired with an explicit screen saver or group policy lock setting.

  • ✗

    User Account Control (UAC)

    Why it's wrong here

    User Account Control (UAC) is an access-control mechanism that prompts for consent or credentials only when a user attempts to perform an administrative operation that requires elevated privileges. It operates on the secure desktop during the elevation prompt and has no timer, session-monitoring code, or post-idle behavior, so it cannot lock the workstation after inactivity. UAC is a security feature, but it addresses privilege boundaries, not device lock requirements.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.