mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: A technician is configuring a new Mac mini for a…
A technician is configuring a new Mac mini for a kiosk application. The kiosk should run only a single web browser in full-screen mode, and users should not be able to exit the app or access the desktop. Which macOS feature should be used to enforce this?
⚠ Common exam trap
A common mix-up: candidates confuse macOS Parental Controls with iOS Guided Access, or assume a nonexistent 'Single App Mode' setting exists in System Settings, leading them to pick A or C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a user account with Parental Controls set to allow only the browser app
MacOS Parental Controls (now part of Screen Time) can restrict a standard user account to a single app, such as a web browser. When configured to 'Allow only this app,' the system prevents the user from switching apps, accessing the desktop, or exiting the browser, which is exactly what a kiosk requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Guided Access in Accessibility settings
Why it's wrong here
Guided Access is an iOS/iPadOS feature designed to restrict a device to a single application, disable certain hardware buttons, and limit touch input areas, effectively creating a kiosk-like experience. This feature is specifically implemented within the mobile operating systems for Apple devices and is not present or configurable within macOS System Settings or Accessibility options. Therefore, it cannot be used to configure a Mac Mini for a single-app purpose.
- ✓
Configure a user account with Parental Controls set to allow only the browser app
Why this is correct
macOS Parental Controls, now integrated into Screen Time settings, allow administrators to precisely manage application access for specific user accounts. By configuring these controls, a technician can restrict a user account to launch and use only a designated application, such as a web browser, preventing access to the desktop, other applications, or system settings. When combined with auto-login for this restricted user and setting the browser as a login item, this effectively creates a robust single-application kiosk environment.
- ✗
Use the 'Single App Mode' setting in System Settings
Why it's wrong here
There is no native 'Single App Mode' setting directly accessible or configurable within macOS System Settings for a standard user or administrator. While Apple devices can be placed into a true Single App Mode, this functionality is typically managed and enforced through Mobile Device Management (MDM) solutions, which push profiles and restrictions to the device. Without an MDM infrastructure, this specific setting is unavailable for local configuration.
- ✗
Set the browser as a Login Item for a standard user
Why it's wrong here
Setting an application as a Login Item merely ensures that the specified application automatically launches when a user logs into their account. While this would open the browser upon login, it does not prevent the user from quitting the application, accessing the macOS desktop, launching other applications, or modifying system settings. Therefore, it fails to create the necessary restricted, single-application environment required for a kiosk setup.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.