220-1102 Security Practice Question
A company uses a policy of least privilege. A user needs to install a software application that requires administrative privileges. The technician has verified the software is approved and safe. What is the BEST way to provide the necessary access?
⚠ Common exam trap
Many candidates confuse 'Run as administrator' with permanently elevating a user's privileges, leading them to choose option A because they think it's simpler, but the exam emphasizes adherence to least privilege policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the 'Run as administrator' context menu with the technician's credentials
It allows the user to run the approved application with administrative privileges only for that specific session, using the technician's credentials. This adheres to the principle of least privilege by not granting the user permanent administrative rights, which would increase security risks. The 'Run as administrator' feature provides temporary elevation without modifying the user's account permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the user to the local Administrators group permanently
Why it's wrong here
Permanently adding the user to the local Administrators group escalates the account's token for every process and logon session, not just the installer. Any application or malware running as that user could read the SAM, alter services, change auditing policies, and install kernel drivers, so the security footprint remains enlarged after the setup finishes. Least privilege requires granting the minimum authority for the specific task, and a one-time software installation does not justify a permanent administrative role.
- ✓
Use the 'Run as administrator' context menu with the technician's credentials
Why this is correct
Right-clicking the setup file and choosing 'Run as administrator' lets the technician type their own admin credentials into the UAC prompt, creating an elevated process token only for that installer. The user's normal profile remains a standard user, and no local group membership is modified, so future operations continue to run at the user's restricted integrity level. This provides a clear audit trail and is the standard approved method under a least-privilege policy.
- ✗
Change the software installation folder permissions
Why it's wrong here
Changing permissions on the installation folder fails to address the full scope of a modern installer, which also writes to HKLM registry keys, service control manager entries, and system directories like C:\Windows\System32. Widening ACLs on the application directory may allow a standard user to replace executables later, introducing a tampering risk, and the install still aborts if it needs an elevated token for non-folder writes. Broadening filesystem rights is not a substitute for proper elevation.
- ✗
Grant the user temporary administrative rights for the installation
Why it's wrong here
Granting temporary administrative rights elevates the whole user account for a period, giving the user the ability to modify other users, change system time, and load drivers—privileges that go far beyond the single installation task. The temporary membership can remain active longer than intended if the removal step is skipped or fails, and it may not be visible in standard reports if it was created through a script or scheduled task. The 'Run as administrator' context menu is more controlled because the elevated token lasts only for the process and is tied to the technician's explicit approval.
Go deeper
Related to this question
Learn chapter
Principle of Least Privilege
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.