Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A security audit reveals that an employee's workstation has software installed that was not approved. The employee claims they downloaded it from the internet. Which principle of least privilege or security policy should prevent unauthorized software installation?

⚠ Common exam trap

Watch out — candidates often confuse antivirus software with proactive installation prevention, but antivirus only reacts to known threats, whereas application whitelisting enforces a policy that blocks all unapproved software regardless of its maliciousness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Application whitelisting

Application whitelisting is the correct answer because it enforces a security policy that only pre-approved software can run on a workstation. By maintaining a list of allowed applications, any unapproved software downloaded from the internet is blocked from executing, directly preventing unauthorized installations regardless of user intent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Application whitelisting

    Why this is correct

    Application whitelisting is a default-deny control: only programs explicitly approved by policy are allowed to execute. This directly prevents a user from installing or running unauthorized software because the installer and the installed binaries are blocked at execution time. Unlike reactive blacklists, it does not rely on knowing the malware in advance, making it the correct control to enforce 'only approved applications may run.'

  • ✗

    Password complexity

    Why it's wrong here

    Password complexity policies govern the strength of user authentication secrets, requiring minimum length, character classes, and sometimes history. They do not govern the operating system's process creation, installation routines, or software execution. Even a user with a highly complex password can install and run arbitrary software if no execution restriction exists, so password complexity is entirely orthogonal to this audit finding.

  • ✗

    Data loss prevention

    Why it's wrong here

    Data loss prevention (DLP) systems inspect data in use, in motion, and at rest to prevent unauthorized exfiltration or leakage of sensitive information. They can block email, USB transfers, or cloud uploads, but they do not evaluate whether a new executable image is approved to be installed. DLP might flag a malicious payload's content after it is already present, but it does not stop the installation or execution of unauthorized software.

  • ✗

    Antivirus software

    Why it's wrong here

    Antivirus software detects known malware through signatures, heuristics, and behavioral monitoring, but it operates on a default-allow model: everything not explicitly flagged as malicious is permitted. This means a custom tool, a renamed legitimate executable, or a zero-day exploit can be installed and run without ever being recognized. An audit finding of unauthorized software is only partially addressed by antivirus, which lacks the default-deny enforcement of an application whitelist.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.