Courseiva
hardMultiple Choice

220-1102 Practice Question: A security incident occurred where an employee's…

A security incident occurred where an employee's workstation was infected with ransomware. The IT manager wants to ensure that all future workstations have Controlled Folder Access enabled to protect critical data from unauthorized changes. Which Windows Security applet should be used to configure this?

⚠ Common exam trap

The trap is assuming that ransomware protection lives under 'Device security' or 'App & browser control' because those sound security-related; the exam expects you to know the exact navigation path under Virus & threat protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Security > Virus & threat protection > Manage ransomware protection

Controlled Folder Access (CFA) is a Windows Defender Exploit Guard feature that protects user folders (Documents, Pictures, Desktop, etc.) from unauthorized modification by untrusted applications, and it is configured under Windows Security > Virus & threat protection > Manage ransomware protection. This is the only applet in the Windows Security UI that exposes the ransomware-specific protections including Controlled Folder Access and OneDrive folder protection. Enabling it here allows admins to whitelist trusted apps while blocking ransomware from encrypting protected directories.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Windows Security > Firewall & network protection

    Why it's wrong here

    Windows Security > Firewall & network protection primarily manages the Windows Defender Firewall, allowing users to configure inbound and outbound network rules for applications and services. This section also controls network profile settings (Public, Private) and enables or disables the firewall itself. However, it does not provide any controls for file system access permissions or specific folder protection against unauthorized modification by local processes, which is distinct from network-based access.

  • ✗

    Windows Security > App & browser control

    Why it's wrong here

    The Windows Security > App & browser control section focuses on settings related to Microsoft Defender SmartScreen, which protects against malicious websites and downloads, and Exploit protection, which hardens system processes against various attack vectors. While these features contribute to overall system integrity and application security, they do not offer the specific functionality to designate and protect user-defined folders from unauthorized write access by applications, a capability provided by Controlled Folder Access.

  • ✗

    Windows Security > Device security

    Why it's wrong here

    Windows Security > Device security provides an overview and configuration options for hardware-based security features, including the Security processor (TPM), Secure boot, and Core isolation (memory integrity). These features establish a robust hardware root of trust and protect critical system components and processes from low-level attacks. However, this section does not manage software-based file system protection mechanisms like Controlled Folder Access, which specifically safeguards user data folders from ransomware and other malicious applications.

  • ✓

    Windows Security > Virus & threat protection > Manage ransomware protection

    Why this is correct

    This is the correct and precise navigation path within Windows Security to configure Controlled Folder Access, a critical component of Microsoft Defender's ransomware protection. Within 'Manage ransomware protection,' users can enable or disable this feature, designate specific folders to be protected from unauthorized modification, and explicitly whitelist legitimate applications that are permitted to make changes to the contents of those protected directories, effectively preventing ransomware from encrypting valuable data.

About these practice questions

One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.