220-1102 Operating Systems Practice Question
A technician needs to configure a Windows 10 Pro workstation so that only a specific IP address (192.168.1.100) can establish Remote Desktop (RDP) connections to it. The technician has already enabled Remote Desktop in System Properties. Which built-in tool should the technician use to restrict the IP address allowed to connect?
⚠ Common exam trap
It's easy for candidates to confuse the 'Remote Desktop Users' group (managed via Local Security Policy or System Properties) with network-layer IP filtering, assuming secpol.msc can restrict by IP address when it only controls user-level access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Defender Firewall with Advanced Security (wf.msc)
Windows Defender Firewall with Advanced Security (wf.msc) allows creating inbound rules that filter traffic by source IP address. By configuring a custom RDP rule (TCP port 3389) with a scope that permits only 192.168.1.100, the technician restricts RDP connections to that specific IP. This is the correct built-in tool for IP-based access control on a local Windows 10 Pro workstation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Local Security Policy (secpol.msc)
Why it's wrong here
Local Security Policy (secpol.msc) is an MMC snap-in focused on account policies, audit policies, user rights assignments, and security options. Although it may expose a Windows Defender Firewall node, that node is only a shortcut to the same firewall snap-in accessible via wf.msc; the tool's native capabilities do not include directly authoring inbound rules with IP address scoping. To restrict RDP to a specific IP, you must open the firewall rule editor specifically, which is the dedicated interface.
- ✓
Windows Defender Firewall with Advanced Security (wf.msc)
Why this is correct
Windows Defender Firewall with Advanced Security (wf.msc) is the correct tool because it lets you create or edit inbound rules with precise scope settings. When configuring a rule for Remote Desktop (TCP 3389), you can specify the 'Remote IP address' in the rule's Scope tab to allow only 192.168.1.100. All other source IP addresses are effectively denied because no matching allow rule exists, and firewall rules are evaluated in order with an implicit deny at the end unless overridden by another rule.
- ✗
Group Policy Management Console (gpmc.msc)
Why it's wrong here
Group Policy Management Console (gpmc.msc) is an enterprise utility for managing Group Policy Objects across an Active Directory domain, not a local workstation configuration tool. It is not installed by default on Windows 10 Pro, and using it to impose an IP restriction on the local firewall would require a domain environment with appropriate GPOs linking and processing. For a standalone workstation, the direct local firewall snap-in is the appropriate and straightforward method, making this option incorrect.
- ✗
Remote Desktop Settings in System Properties
Why it's wrong here
Remote Desktop Settings in System Properties (sysdm.cpl) merely toggles whether Remote Desktop is enabled and whether Network Level Authentication is required. It offers no interface for restricting incoming connections by source IP address; once Remote Desktop is enabled, any client with valid credentials can attempt a connection. IP-based access control must be implemented at the firewall layer, such as through an inbound rule in wf.msc, not in the Remote Desktop enablement dialog.
Visual reference
Go deeper
Related to this question
Learn chapter
Remote Desktop Protocol (RDP)
Key term
Windows 10
Windows 10 is a personal computer operating system developed by Microsoft that combines the familiarity of Windows 7 with the modern features of Windows 8, designed to run on a wide range of devices from desktops to tablets.
Key term
Windows Defender
Windows Defender is a built-in antimalware and security tool in Microsoft Windows that protects your computer from viruses, spyware, and other malicious software without needing to install anything extra.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.