Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A security auditor discovers that a Windows 10 workstation has the Guest account enabled and is a member of the Administrators group. Which security principle has been violated?

⚠ Common exam trap

Many candidates confuse 'least privilege' with 'separation of duties' because both involve limiting access, but separation of duties specifically requires splitting tasks across multiple accounts, not simply reducing permissions on a single account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Least privilege

The Guest account being a member of the Administrators group violates the principle of least privilege, which states that users and accounts should be granted only the minimum permissions necessary to perform their tasks. By elevating the Guest account to an administrator, the system grants full administrative rights to an account intended for limited, temporary access, creating a severe security risk. This configuration allows any user who can log in as Guest to have unrestricted control over the workstation, including installing software, modifying system settings, and accessing all files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Least privilege

    Why this is correct

    Least privilege is the security principle that grants users only the permissions essential to their role. By assigning administrative rights to the Guest account, the workstation violates this principle, giving an unprivileged, often unauthenticated account complete control over system settings, installed software, and user data. This excessive access expands the attack surface and is exactly what least privilege is designed to prevent.

  • ✗

    Separation of duties

    Why it's wrong here

    Separation of duties is an internal control that prevents any single individual from controlling conflicting tasks, such as approving and executing a financial transaction. The finding of an over-privileged Guest account involves a single account's permission set, not the division of responsibilities among different users or processes. Therefore, this concept does not address the excessive administrative access observed.

  • ✗

    Defense in depth

    Why it's wrong here

    Defense in depth is a layered security strategy that combines multiple controls—firewalls, intrusion detection, antivirus, and access restrictions—to create redundant protection. The auditor identified a single misconfiguration where the Guest account was granted admin rights, which is a privilege issue, not an absence of these independent security layers. Even a robust defense-in-depth architecture would still require correct privilege assignments to be effective.

  • ✗

    Change management

    Why it's wrong here

    Change management is the formal governance process for planning, approving, testing, and documenting modifications to systems to ensure stability and security. The discovered configuration, Guest with administrative rights, may have been introduced without proper authorization, but the core finding is the permission state itself, not a failure to follow the change control procedure. Thus, change management principles are not directly violated by the account's excessive privileges.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A user is able to access a shared folder containing financial reports that are not required for their job role. Which security principle is being violated?

medium
  • ✓ A.Least privilege
  • B.Defense in depth
  • C.Mandatory access control
  • D.Role-based access control

Why A: The principle of least privilege states that users should be granted only the minimum access rights necessary to perform their job functions. A user accessing financial reports unrelated to their role has more access than required, directly violating least privilege. The other options describe broader security strategies or access control models, not the specific principle being breached.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.