hardMultiple Choice
220-1102 net user /delete Practice Question
A security audit reveals that a Windows 10 workstation has an unauthorized local user account. You need to remove this account from the command line without using the GUI. Which command should you use?
⚠ Common exam trap
CompTIA often tests the distinction between deleting a user account (`net user /delete`) and removing a user from a group (`net localgroup /delete`), trapping candidates who confuse group membership removal with account deletion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
net user UnauthorizedUser /delete
The `net user UnauthorizedUser /delete` command correctly removes a local user account from the command line. The `net user` command is designed to manage local user accounts, and the `/delete` switch removes the specified account from the local Security Accounts Manager (SAM) database. This is the standard Windows CLI tool for deleting a local user without using the GUI.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
net localgroup Administrators UnauthorizedUser /delete
Why it's wrong here
This removes the account only from the Administrators group, leaving the user account itself intact and still able to log on. It is the right command when revoking a user's administrative rights while retaining their standard account, which is not the audit requirement here.
- ✓
net user UnauthorizedUser /delete
Why this is correct
The net user command with the /delete switch removes a local account directly from the command line, satisfying the stem's no-GUI constraint. It targets the local SAM database on the workstation, unlike domain-level tools such as Remove-ADUser, which would not affect a local account.
- ✗
wmic useraccount where name='UnauthorizedUser' delete
Why it's wrong here
WMIC's useraccount delete removes the account from the SAM database, but WMIC is deprecated in Windows 10 and later, and the command can fail silently or leave profile remnants. It would be chosen for scripted bulk account cleanup on legacy systems where WMIC is still supported.
- ✗
gpresult /r
Why it's wrong here
Gpresult displays resultant set of policy and Group Policy application details for a user or computer; it performs no account modification whatsoever. It is the correct tool when diagnosing why policy settings are or are not applying, not for deleting an unauthorised local account.
Go deeper
Related to this question
Learn chapter
Windows Command Line Tools
Key term
GUI
A Graphical User Interface (GUI) is a visual way for users to interact with a computer or device using icons, buttons, and windows instead of typing text commands.
Key term
CLI
A CLI (command-line interface) is a text-based way to interact with a computer's operating system by typing commands instead of clicking icons.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.