220-1102 Security Practice Question
A technician finds a USB flash drive in the company parking lot. Out of curiosity, the technician plugs it into a workstation. Immediately, a program runs automatically and installs malware. Which security configuration could have prevented the automatic execution of the malware?
⚠ Common exam trap
CompTIA often tests the distinction between AutoRun (automatic execution of a program) and AutoPlay (automatic prompt for user action), leading candidates to confuse the two and incorrectly choose antivirus or UAC as the solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable AutoRun on removable drives
Disabling AutoRun on removable drives prevents the operating system from automatically executing code (such as an autorun.inf file) when a USB flash drive is inserted. In this scenario, the malware ran automatically because AutoRun was enabled, allowing the malicious program to launch without user interaction. Disabling this feature stops the automatic execution, requiring manual user action to run any files from the drive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable User Account Control (UAC)
Why it's wrong here
UAC prompts for elevation when a program requests administrative privileges, but malware can bypass this by executing with the current user's standard token. The AutoRun flaw triggers code automatically at device insertion, before UAC ever appears, since many malicious payloads do not require admin rights to run. Enabling UAC therefore provides no protection against the initial autorun-based infection vector on the USB drive.
- ✓
Disable AutoRun on removable drives
Why this is correct
Disabling AutoRun on removable drives prevents Windows from automatically executing any program referenced by an autorun.inf file on the inserted USB drive. This severs the initial infection vector at the point of insertion, before any code runs or user interaction occurs. It is a foundational control against USB-borne malware, as it stops the automatic invocation of malicious executables that legacy AutoRun behavior would otherwise trigger.
- ✗
Enable BitLocker on the workstation
Why it's wrong here
BitLocker provides full-disk encryption for the workstation's internal volumes, protecting data confidentiality at rest, but it does nothing to inspect or sandbox code from external media. The USB drive is a separate device and its contents are not decrypted or filtered by the host's BitLocker configuration. Because the threat is malicious code execution from the USB, not unauthorized data access, BitLocker is entirely orthogonal to preventing an AutoRun attack.
- ✗
Install antivirus software
Why it's wrong here
Antivirus software relies on signatures, heuristics, and behavioral monitoring, but the AutoRun-triggered executable launches automatically and immediately upon device insertion, often before the AV scanner has a chance to inspect the file. While endpoint protection may eventually detect and quarantine the threat, it is a reactive measure that does not prevent the autorun mechanism from initiating execution in the first place. Additionally, zero-day or polymorphic malware can evade detection entirely, making AV an insufficient safeguard against this specific vector.
Go deeper
Related to this question
Learn chapter
Malware Types and Removal
Key term
Universal Serial Bus
A Universal Serial Bus (USB) is a standard interface that allows you to connect devices like keyboards, mice, storage drives, and printers to a computer for data transfer and power delivery.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.