220-1102 Operating Systems Practice Question
A standard user tries to run a legacy application that requires administrator privileges on Windows 10. Which prompt will the user see?
⚠ Common exam trap
Test-takers frequently confuse the UAC prompt types, mistakenly thinking that all users see the same 'Yes/No' consent dialog, when in fact standard users see a credential prompt and administrators see a consent prompt.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A UAC prompt asking for administrator credentials.
When a standard user attempts to run a legacy application that requires administrator privileges, Windows 10 triggers a UAC prompt that requests the credentials of an administrator account. This is because the application's manifest specifies 'requireAdministrator' or it is detected as needing elevation, and the user is not an administrator, so UAC displays a credential prompt rather than a simple consent dialog.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A UAC prompt asking for administrator credentials.
Why this is correct
Standard users operate under a restricted token, and UAC requires explicit elevation for processes that request administrator privileges. Since the legacy application's manifest declares requireAdministrator, the AppInfo service identifies the need for elevation and displays a credential prompt, demanding an account name and password of a member of the local Administrators group. Only after valid administrator credentials are supplied does the application launch with the elevated token.
- ✗
A UAC prompt asking for confirmation with the option 'Yes' or 'No'.
Why it's wrong here
The yes/no consent prompt is exclusively shown to users who are already members of the Administrators group, because their full token can be elevated without re-authentication. A standard user does not possess an elevated token to grant; instead, UAC invokes the credential UI (secure desktop) to obtain a separate administrator account's password. Therefore, seeing a simple Yes/No confirmation would indicate the user is an administrator, which contradicts the scenario's premise of a standard user.
- ✗
An 'Access Denied' error message.
Why it's wrong here
UAC does not immediately deny the launch; it intercepts the CreateProcess call and presents the credential prompt before any ACL check occurs. An 'Access Denied' error would arise only if the user cancels the credential dialog three consecutive times or enters credentials for an account that lacks administrator rights. In normal operation, the system waits for valid elevation, so a bare access-denied message without an intervening prompt is not the standard UAC behavior for a legacy application that requires elevation.
- ✗
The application runs without any prompt because UAC is disabled.
Why it's wrong here
If UAC were disabled, the legacy application might run without a prompt, but the question does not state that UAC is turned off, and Windows defaults to UAC enabled. Moreover, disabling UAC is a significant security degradation that loads all processes with full tokens, making the system vulnerable to malware that can silently modify system files. The scenario asks what a standard user would encounter in a typical, default-configured environment, so assuming UAC is disabled is unsupported and does not reflect the expected correct behavior.
Go deeper
Related to this question
Learn chapter
User Account Control (UAC)
Key term
UAC
User Account Control is a Windows security feature that prevents unauthorized changes to your computer by asking for permission before allowing certain actions.
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.