Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A security audit reveals that several workstations have unauthorized applications installed. The users claim they did not install the software. Which security control would have been MOST effective in preventing this situation?

⚠ Common exam trap

Test-takers frequently assume antivirus software is the catch-all solution for unauthorized software, but it only addresses malicious code, not policy violations involving non-malicious applications.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Application whitelisting

Application whitelisting is the most effective control because it explicitly defines which applications are permitted to run on a system. By default, any application not on the whitelist is blocked from executing, preventing unauthorized software from being installed or run, regardless of how it arrived on the workstation. This addresses the root cause—unauthorized applications—by enforcing a deny-by-default policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Application whitelisting

    Why this is correct

    Application whitelisting enforces a deny-by-default execution policy: only binaries, scripts, and DLLs that match approved cryptographic hashes or publisher certificates are permitted to start. Because unauthorized software's installer is not on the approved list, it cannot run at all, preventing installation before it begins. This control operates at the OS security hook level, not relying on signature databases.

  • ✗

    Antivirus software

    Why it's wrong here

    Antivirus software is a reactive, signature-based control that detects files resembling known malware or suspicious heuristics; it does not evaluate whether an application is authorized by an organization. A non-malicious, unapproved program (e.g., a personal game or a trial utility) will install and run without any AV alert because it lacks malicious signatures. Thus AV addresses threats, not policy compliance.

  • ✗

    Host-based firewall

    Why it's wrong here

    A host-based firewall inspects network packets based on rules for ports, IP addresses, and protocols, filtering traffic that enters or leaves the host. It has no mechanism to inspect or block file system writes, registry modifications, or process creation, so application installation proceeds unaffected. Even if a rule blocks a program's network communication after installation, the software is already present on the system.

  • ✗

    Data encryption

    Why it's wrong here

    Data encryption (e.g., BitLocker, EFS) protects data at rest by converting it into ciphertext that requires the proper key to read; it does not authenticate or restrict which executables can be launched. An authenticated user can install software and the encryption layer will simply encrypt the new files, treating them like any other data. Therefore, encryption ensures confidentiality, not system integrity or authorization.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.