Courseiva
hardMultiple Choice

220-1102 net user /delete Practice Question

A security audit reveals that a Windows 10 workstation has an unauthorized local user account. You need to remove this account from the command line without using the GUI. Which command should you use?

⚠ Common exam trap

CompTIA often tests the distinction between deleting a user account (`net user /delete`) and removing a user from a group (`net localgroup /delete`), trapping candidates who confuse group membership removal with account deletion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

net user UnauthorizedUser /delete

The `net user UnauthorizedUser /delete` command correctly removes a local user account from the command line. The `net user` command is designed to manage local user accounts, and the `/delete` switch removes the specified account from the local Security Accounts Manager (SAM) database. This is the standard Windows CLI tool for deleting a local user without using the GUI.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    net localgroup Administrators UnauthorizedUser /delete

    Why it's wrong here

    This removes the account only from the Administrators group, leaving the user account itself intact and still able to log on. It is the right command when revoking a user's administrative rights while retaining their standard account, which is not the audit requirement here.

  • ✓

    net user UnauthorizedUser /delete

    Why this is correct

    The net user command with the /delete switch removes a local account directly from the command line, satisfying the stem's no-GUI constraint. It targets the local SAM database on the workstation, unlike domain-level tools such as Remove-ADUser, which would not affect a local account.

  • ✗

    wmic useraccount where name='UnauthorizedUser' delete

    Why it's wrong here

    WMIC's useraccount delete removes the account from the SAM database, but WMIC is deprecated in Windows 10 and later, and the command can fail silently or leave profile remnants. It would be chosen for scripted bulk account cleanup on legacy systems where WMIC is still supported.

  • ✗

    gpresult /r

    Why it's wrong here

    Gpresult displays resultant set of policy and Group Policy application details for a user or computer; it performs no account modification whatsoever. It is the correct tool when diagnosing why policy settings are or are not applying, not for deleting an unauthorised local account.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.