220-1102 Security Practice Question
A company has a policy that requires all workstations to have antivirus software installed and keep it up to date. A technician finds that several computers have disabled their antivirus services. Which security control would have MOST effectively prevented users from disabling the antivirus?
⚠ Common exam trap
It's easy for candidates to confuse 'preventing execution' (whitelisting) with 'preventing service disablement' (Group Policy), or assume UAC blocks all administrative actions, when in reality UAC only prompts for consent and does not enforce service state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Group Policy settings to enforce antivirus protection
Group Policy settings can enforce antivirus protection by configuring Windows Security Center policies (e.g., 'Turn off Windows Defender' disabled) and monitoring services like WinDefend or McAfee via Security Center. This prevents users from disabling the antivirus service through local control panel or services.msc, as the policy overrides local changes and can re-enable the service at next Group Policy refresh.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Group Policy settings to enforce antivirus protection
Why this is correct
Group Policy provides centralized, domain-level configuration that can force Windows Defender (or third-party antivirus via ADMX templates) to remain active, override local user changes at the next policy refresh, and even hide or disable users' ability to turn off real-time protection. Unlike user-level prompts, this is a machine-level enforcement mechanism that applies consistently to every workstation. It is the correct answer because it satisfies the policy requirement by both enabling antivirus and preventing users from stopping it.
- ✗
Application whitelisting
Why it's wrong here
Application whitelisting, such as AppLocker or WDAC, restricts which executables, scripts, and DLLs are allowed to run, but it does not control the running state of a permitted service like antivirus. A user with administrative rights could still manually stop the antivirus service through Services.msc or PowerShell, and whitelisting would not block that allowed management action. Thus, while whitelisting adds security, it cannot enforce that antivirus protection remains active across workstations.
- ✗
User Account Control (UAC)
Why it's wrong here
User Account Control (UAC) is an elevation consent mechanism that prompts for administrator approval when a process requests higher privileges, but a local administrator can simply click 'Yes' to any prompt, including one from a script disabling antivirus. It does not centrally enforce a desired state, nor does it prevent an admin from making legitimate but policy-violating changes. Because the policy requires a mandatory, consistent result, UAC's user-interactive approval is insufficient.
- ✗
Data Execution Prevention (DEP)
Why it's wrong here
Data Execution Prevention (DEP) is a hardware- and software-based memory protection feature that marks certain memory regions as non-executable to block buffer overflow attacks; it has no role in managing antivirus services or their configuration. DEP neither enables nor enforces antivirus, and it does not stop a user from disabling a security service through normal operating system interfaces. Therefore, it is unrelated to the policy requirement that all workstations run antivirus.
Go deeper
Related to this question
Learn chapter
Account Lockout Policies
Key term
Antivirus
Antivirus is software that detects, prevents, and removes malicious software (malware) from a computer or network.
Key term
Control Panel
Control Panel is a central graphical interface in Windows operating systems used to configure system settings, manage hardware, and control user preferences.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.