Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company has a policy that requires all workstations to have antivirus software installed and keep it up to date. A technician finds that several computers have disabled their antivirus services. Which security control would have MOST effectively prevented users from disabling the antivirus?

⚠ Common exam trap

It's easy for candidates to confuse 'preventing execution' (whitelisting) with 'preventing service disablement' (Group Policy), or assume UAC blocks all administrative actions, when in reality UAC only prompts for consent and does not enforce service state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Group Policy settings to enforce antivirus protection

Group Policy settings can enforce antivirus protection by configuring Windows Security Center policies (e.g., 'Turn off Windows Defender' disabled) and monitoring services like WinDefend or McAfee via Security Center. This prevents users from disabling the antivirus service through local control panel or services.msc, as the policy overrides local changes and can re-enable the service at next Group Policy refresh.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Group Policy settings to enforce antivirus protection

    Why this is correct

    Group Policy provides centralized, domain-level configuration that can force Windows Defender (or third-party antivirus via ADMX templates) to remain active, override local user changes at the next policy refresh, and even hide or disable users' ability to turn off real-time protection. Unlike user-level prompts, this is a machine-level enforcement mechanism that applies consistently to every workstation. It is the correct answer because it satisfies the policy requirement by both enabling antivirus and preventing users from stopping it.

  • ✗

    Application whitelisting

    Why it's wrong here

    Application whitelisting, such as AppLocker or WDAC, restricts which executables, scripts, and DLLs are allowed to run, but it does not control the running state of a permitted service like antivirus. A user with administrative rights could still manually stop the antivirus service through Services.msc or PowerShell, and whitelisting would not block that allowed management action. Thus, while whitelisting adds security, it cannot enforce that antivirus protection remains active across workstations.

  • ✗

    User Account Control (UAC)

    Why it's wrong here

    User Account Control (UAC) is an elevation consent mechanism that prompts for administrator approval when a process requests higher privileges, but a local administrator can simply click 'Yes' to any prompt, including one from a script disabling antivirus. It does not centrally enforce a desired state, nor does it prevent an admin from making legitimate but policy-violating changes. Because the policy requires a mandatory, consistent result, UAC's user-interactive approval is insufficient.

  • ✗

    Data Execution Prevention (DEP)

    Why it's wrong here

    Data Execution Prevention (DEP) is a hardware- and software-based memory protection feature that marks certain memory regions as non-executable to block buffer overflow attacks; it has no role in managing antivirus services or their configuration. DEP neither enables nor enforces antivirus, and it does not stop a user from disabling a security service through normal operating system interfaces. Therefore, it is unrelated to the policy requirement that all workstations run antivirus.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.