hardMultiple ChoiceObjective-mapped
220-1102 Practice Question: Deploy a custom security policy to all Windows 10…
A technician needs to deploy a custom security policy to all Windows 10 workstations in a small office. The policy must restrict access to the Control Panel and prevent users from changing system settings. Which administrative tool should be used to create and apply this policy locally on each machine?
⚠ Common exam trap
A common misconception is that Local Security Policy (secpol.msc) can handle all policy restrictions, but it only covers security-specific settings, not administrative templates for UI restrictions like Control Panel access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Local Group Policy Editor (gpedit.msc)
The Local Group Policy Editor (gpedit.msc) is the correct tool because it provides the administrative templates and policy nodes (e.g., User Configuration > Administrative Templates > Control Panel) needed to restrict access to Control Panel and prevent system setting changes. These settings are written to the local Group Policy Objects (GPOs) stored in %SystemRoot%\System32\GroupPolicy, which Windows applies at user logon. This tool is available on Windows 10 Pro, Enterprise, and Education editions, but not on Windows 10 Home.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Local Security Policy (secpol.msc)
Why it's wrong here
Local Security Policy (secpol.msc) is primarily used to configure specific security settings for a local computer, such as account lockout policies, password complexity requirements, audit policies, and user rights assignments. While it deals with security, it does not offer the granular administrative templates required to deploy custom security policies that restrict access to system components like the Control Panel or specific applications, which is a common aspect of custom security policies.
- ✗
User Accounts (netplwiz)
Why it's wrong here
User Accounts (netplwiz) is a utility focused on managing user accounts, including adding or removing users, changing passwords, and configuring automatic login settings. Its primary function is user credential and group membership management. It lacks the capabilities to implement system-wide or user-specific restrictions on accessing operating system features, such as hiding Control Panel items or disabling specific system utilities, which are typical components of a custom security policy.
- ✓
Local Group Policy Editor (gpedit.msc)
Why this is correct
Local Group Policy Editor (gpedit.msc) is the appropriate tool for deploying custom security policies on a standalone Windows machine. It provides extensive administrative templates under both Computer Configuration and User Configuration, allowing technicians to configure granular settings. These settings include restricting access to the Control Panel, disabling specific system features, enforcing software restrictions, and managing user environments, making it ideal for implementing comprehensive custom security policies.
- ✗
System Configuration (msconfig)
Why it's wrong here
System Configuration (msconfig) is a diagnostic tool primarily used to manage boot options, startup programs, services, and system tools for troubleshooting purposes. It allows users to enable or disable startup items and services to identify performance issues or conflicts. However, msconfig does not offer any functionality for defining or deploying custom security policies, such as restricting user access to system features or enforcing specific user environment configurations.
Go deeper
Related to this question
Learn chapter
Windows Editions and Features
Key term
Security policy
A security policy is a formal set of rules and guidelines that an organization establishes to protect its information assets and technology resources.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.