220-1102 Operational Procedures Practice Question
A user requests local administrator access on their workstation to install a software program. The company follows the principle of least privilege. What should the technician do?
⚠ Common exam trap
A common mix-up: candidates think obtaining manager approval (Option C) justifies granting admin access, but the principle of least privilege requires avoiding permanent elevation regardless of approval, and the correct action is to perform the installation without granting the user admin rights.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Install the software for the user using an administrative account.
The principle of least privilege dictates that users should only have the minimum permissions necessary to perform their job functions. Granting a user local administrator access violates this principle by providing unnecessary elevated rights, which could lead to security risks such as malware installation or system misconfiguration. Instead, the technician should use an administrative account to install the software on the user's behalf, ensuring the software is installed without permanently elevating the user's privileges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Grant administrator access to the user.
Why it's wrong here
Granting administrator access to the user's account permanently elevates their privileges well beyond the single software installation they requested. This directly violates the principle of least privilege, expanding the attack surface for malware and unauthorized system changes. Once the installation is complete, the user retains the ability to modify system files, install additional software, and alter security settings, which is unnecessary and risky.
- ✓
Install the software for the user using an administrative account.
Why this is correct
Having a technician perform the installation with a separate administrative account is the correct approach because it provides the necessary elevated privileges only for the duration of the task. The user's primary account remains a standard user, preserving the least privilege model and reducing the risk of accidental or malicious system modifications. This method also allows for centralized auditing, as administrative actions are traceable to the technician's account rather than the user.
- ✗
Advise the user to contact their manager for approval, then grant access.
Why it's wrong here
Requiring managerial approval before granting administrator access adds a bureaucratic step but does not change the fundamental security flaw: the user still receives permanent administrative privileges for what is likely a one-time need. The approval process may legitimize the request, but it does not justify violating least privilege, and the technician should instead perform the installation directly. Even with approval, the elevated access remains on the user's account, exposing the system to unnecessary risk long after the software is installed.
- ✗
Create a separate administrator account for the user.
Why it's wrong here
Creating a separate administrator account for the user still grants them persistent elevated privileges, which is more than needed for a single installation. While it separates the administrative account from the user's daily-use account, the user can still log into that admin account and perform any privileged action, violating least privilege and increasing the risk of credential theft or misuse. The proper solution is to have a technician use an existing administrative account to perform the installation, rather than providing the user with any standing administrative access.
Go deeper
Related to this question
Learn chapter
Troubleshoot: Malware Infections
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.