Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company uses a policy of least privilege. A user needs to install a software application that requires administrative privileges. The technician has verified the software is approved and safe. What is the BEST way to provide the necessary access?

⚠ Common exam trap

Many candidates confuse 'Run as administrator' with permanently elevating a user's privileges, leading them to choose option A because they think it's simpler, but the exam emphasizes adherence to least privilege policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the 'Run as administrator' context menu with the technician's credentials

It allows the user to run the approved application with administrative privileges only for that specific session, using the technician's credentials. This adheres to the principle of least privilege by not granting the user permanent administrative rights, which would increase security risks. The 'Run as administrator' feature provides temporary elevation without modifying the user's account permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add the user to the local Administrators group permanently

    Why it's wrong here

    Permanently adding the user to the local Administrators group escalates the account's token for every process and logon session, not just the installer. Any application or malware running as that user could read the SAM, alter services, change auditing policies, and install kernel drivers, so the security footprint remains enlarged after the setup finishes. Least privilege requires granting the minimum authority for the specific task, and a one-time software installation does not justify a permanent administrative role.

  • ✓

    Use the 'Run as administrator' context menu with the technician's credentials

    Why this is correct

    Right-clicking the setup file and choosing 'Run as administrator' lets the technician type their own admin credentials into the UAC prompt, creating an elevated process token only for that installer. The user's normal profile remains a standard user, and no local group membership is modified, so future operations continue to run at the user's restricted integrity level. This provides a clear audit trail and is the standard approved method under a least-privilege policy.

  • ✗

    Change the software installation folder permissions

    Why it's wrong here

    Changing permissions on the installation folder fails to address the full scope of a modern installer, which also writes to HKLM registry keys, service control manager entries, and system directories like C:\Windows\System32. Widening ACLs on the application directory may allow a standard user to replace executables later, introducing a tampering risk, and the install still aborts if it needs an elevated token for non-folder writes. Broadening filesystem rights is not a substitute for proper elevation.

  • ✗

    Grant the user temporary administrative rights for the installation

    Why it's wrong here

    Granting temporary administrative rights elevates the whole user account for a period, giving the user the ability to modify other users, change system time, and load drivers—privileges that go far beyond the single installation task. The temporary membership can remain active longer than intended if the removal step is skipped or fails, and it may not be visible in standard reports if it was created through a script or scheduled task. The 'Run as administrator' context menu is more controlled because the elevated token lasts only for the process and is tied to the technician's explicit approval.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.