220-1102 Group Policy Practice Question
A security audit reveals that several employees have been using weak passwords that can be easily guessed. The company wants to enforce stronger password policies on all Windows 10 computers. Which tool should the administrator use to configure and enforce password complexity requirements?
⚠ Common exam trap
Candidates may assume that Local Security Policy is the correct tool because it is commonly used for local password policies. However, for domain-joined computers, Group Policy takes precedence and is the appropriate tool.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Local Security Policy
Local Security Policy is the appropriate tool for configuring password complexity requirements on local Windows 10 computers. For domain-joined computers, Group Policy would be used instead, but in this scenario, the computers are not specified as domain-joined, so Local Security Policy is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Local Security Policy
Why this is correct
Local Security Policy (secpol.msc) is the correct console for configuring local password policies, including complexity, length, history, and lockout thresholds, but it applies exclusively to the computer's SAM database. In a domain environment, Group Policy from Active Directory overrides these local settings for domain user accounts, so while it works for standalone workstations, it cannot force consistent policy across all domain-joined computers. Because the audit targets all employees' computers, a centrally managed GPO—not the local policy—is the appropriate mechanism.
- ✗
Device Manager
Why it's wrong here
Device Manager (devmgmt.msc) is a hardware management snap-in that lists installed devices, drivers, and their resource usage, letting you disable, uninstall, or update driver software. It contains no password or account security settings whatsoever—password complexity is an authentication policy, not a hardware attribute. Therefore, it cannot be used to enforce or modify password requirements on any computer.
- ✗
User Accounts Control Panel
Why it's wrong here
The User Accounts Control Panel applet provides a simplified interface for creating local users, resetting passwords, and adjusting User Account Control (UAC) notification levels, but it does not expose policy settings like password complexity, minimum length, or account lockout. These settings live in the security policy database and must be configured via secpol.msc, gpedit.msc, or net accounts. The applet is for day-to-day account administration, not for system-wide security policy definition.
- ✗
Windows Defender Firewall
Why it's wrong here
Windows Defender Firewall (wf.msc) defines inbound and outbound network-traffic rules based on ports, IP addresses, and applications, and it is a core network-security component. It has no influence over how Windows authenticates users or sets password-complexity requirements, because that logic resides in the Local Security Authority and SAM. Firewall rules filter traffic, not credential policies, so they cannot be used to enforce password guidelines across the company.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
Key term
Group Policy
Group Policy is a Windows-based feature that allows administrators to centrally manage and enforce settings for users and computers across an organization.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.