Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A security audit reveals that multiple workstations have unauthorized software installed despite a policy allowing only approved software. Users have local administrative rights. Which security control would best prevent this in the future?

⚠ Common exam trap

Test-takers frequently confuse the purpose of antivirus software as a preventive control against unauthorized software, when in reality it only reacts to known threats and does not enforce an allow-list policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Application whitelisting

Application whitelisting is the correct choice because it explicitly defines a list of approved applications that are allowed to run on a workstation. By default, any software not on the whitelist is blocked from executing, regardless of user permissions. This directly addresses the scenario where users with local administrative rights can install unauthorized software, as the whitelisting policy overrides their ability to run unapproved executables.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Application whitelisting

    Why this is correct

    Application whitelisting is a proactive, default-deny security control that only permits execution of applications explicitly listed in an approved policy. Because the kernel enforces the allowlist regardless of the user's privilege level, even a user with local administrative rights cannot launch or install unapproved executables. This directly prevents unauthorized software from running on workstations, which is precisely what the audit found, making it the most effective solution among the choices.

  • ✗

    Antivirus software

    Why it's wrong here

    Antivirus software is a reactive, blacklist-based tool that uses signatures and heuristics to detect known malicious code, but it does not restrict software installation by default. It will not block an unapproved application simply because it is legitimate from an antivirus perspective, since the software may be innocuous but non-compliant with policy. Even with real-time protection enabled, antivirus does not enforce an allowlist and can be easily disabled or bypassed by a user with administrative rights.

  • ✗

    Software restriction policies

    Why it's wrong here

    Software restriction policies are designed to prevent the execution of unapproved applications by standard users, typically through rules based on hash, path, or digital certificate. However, they fail in this scenario because users possessing local administrative rights can easily disable or bypass these policies, as administrators have full control over their workstation's local security configuration. This option is tempting because SRPs do restrict software, and they would be an effective control to prevent non-administrative users from installing or running unauthorized programs, thereby enforcing compliance for typical user accounts.

  • ✗

    Patch management

    Why it's wrong here

    Patch management is an operational process for deploying vendor updates to fix vulnerabilities in existing OS and application versions, but it has no capability to control which applications may be installed or executed. A user with local administrative rights can still install and run unapproved software, as patch management only maintains the security of approved software that is already present. It addresses the risk of unpatched flaws, not the risk of unauthorized software installation that the audit identified.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security audit reveals that an employee's workstation has software installed that was not approved. The employee claims they downloaded it from the internet. Which principle of least privilege or security policy should prevent unauthorized software installation?

hard
  • ✓ A.Application whitelisting
  • B.Password complexity
  • C.Data loss prevention
  • D.Antivirus software

Why A: Application whitelisting is the correct answer because it enforces a security policy that only pre-approved software can run on a workstation. By maintaining a list of allowed applications, any unapproved software downloaded from the internet is blocked from executing, directly preventing unauthorized installations regardless of user intent.

Variation 2. A security audit reveals that several workstations have unauthorized applications installed. The users claim they did not install the software. Which security control would have been MOST effective in preventing this situation?

medium
  • ✓ A.Application whitelisting
  • B.Antivirus software
  • C.Host-based firewall
  • D.Data encryption

Why A: Application whitelisting is the most effective control because it explicitly defines which applications are permitted to run on a system. By default, any application not on the whitelist is blocked from executing, preventing unauthorized software from being installed or run, regardless of how it arrived on the workstation. This addresses the root cause—unauthorized applications—by enforcing a deny-by-default policy.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.