Courseiva
Security →hardMultiple Choice

220-1102 Group Policy Practice Question

A security audit reveals that several employees have been using weak passwords that can be easily guessed. The company wants to enforce stronger password policies on all Windows 10 computers. Which tool should the administrator use to configure and enforce password complexity requirements?

⚠ Common exam trap

Candidates may assume that Local Security Policy is the correct tool because it is commonly used for local password policies. However, for domain-joined computers, Group Policy takes precedence and is the appropriate tool.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Local Security Policy

Local Security Policy is the appropriate tool for configuring password complexity requirements on local Windows 10 computers. For domain-joined computers, Group Policy would be used instead, but in this scenario, the computers are not specified as domain-joined, so Local Security Policy is correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Local Security Policy

    Why this is correct

    Local Security Policy (secpol.msc) is the correct console for configuring local password policies, including complexity, length, history, and lockout thresholds, but it applies exclusively to the computer's SAM database. In a domain environment, Group Policy from Active Directory overrides these local settings for domain user accounts, so while it works for standalone workstations, it cannot force consistent policy across all domain-joined computers. Because the audit targets all employees' computers, a centrally managed GPO—not the local policy—is the appropriate mechanism.

  • ✗

    Device Manager

    Why it's wrong here

    Device Manager (devmgmt.msc) is a hardware management snap-in that lists installed devices, drivers, and their resource usage, letting you disable, uninstall, or update driver software. It contains no password or account security settings whatsoever—password complexity is an authentication policy, not a hardware attribute. Therefore, it cannot be used to enforce or modify password requirements on any computer.

  • ✗

    User Accounts Control Panel

    Why it's wrong here

    The User Accounts Control Panel applet provides a simplified interface for creating local users, resetting passwords, and adjusting User Account Control (UAC) notification levels, but it does not expose policy settings like password complexity, minimum length, or account lockout. These settings live in the security policy database and must be configured via secpol.msc, gpedit.msc, or net accounts. The applet is for day-to-day account administration, not for system-wide security policy definition.

  • ✗

    Windows Defender Firewall

    Why it's wrong here

    Windows Defender Firewall (wf.msc) defines inbound and outbound network-traffic rules based on ports, IP addresses, and applications, and it is a core network-security component. It has no influence over how Windows authenticates users or sets password-complexity requirements, because that logic resides in the Local Security Authority and SAM. Firewall rules filter traffic, not credential policies, so they cannot be used to enforce password guidelines across the company.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.