Courseiva
Operating Systems →mediumMultiple Choice

220-1102 Operating Systems Practice Question

A technician needs to configure a Windows 10 Pro workstation so that only a specific IP address (192.168.1.100) can establish Remote Desktop (RDP) connections to it. The technician has already enabled Remote Desktop in System Properties. Which built-in tool should the technician use to restrict the IP address allowed to connect?

⚠ Common exam trap

It's easy for candidates to confuse the 'Remote Desktop Users' group (managed via Local Security Policy or System Properties) with network-layer IP filtering, assuming secpol.msc can restrict by IP address when it only controls user-level access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Defender Firewall with Advanced Security (wf.msc)

Windows Defender Firewall with Advanced Security (wf.msc) allows creating inbound rules that filter traffic by source IP address. By configuring a custom RDP rule (TCP port 3389) with a scope that permits only 192.168.1.100, the technician restricts RDP connections to that specific IP. This is the correct built-in tool for IP-based access control on a local Windows 10 Pro workstation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Local Security Policy (secpol.msc)

    Why it's wrong here

    Local Security Policy (secpol.msc) is an MMC snap-in focused on account policies, audit policies, user rights assignments, and security options. Although it may expose a Windows Defender Firewall node, that node is only a shortcut to the same firewall snap-in accessible via wf.msc; the tool's native capabilities do not include directly authoring inbound rules with IP address scoping. To restrict RDP to a specific IP, you must open the firewall rule editor specifically, which is the dedicated interface.

  • ✓

    Windows Defender Firewall with Advanced Security (wf.msc)

    Why this is correct

    Windows Defender Firewall with Advanced Security (wf.msc) is the correct tool because it lets you create or edit inbound rules with precise scope settings. When configuring a rule for Remote Desktop (TCP 3389), you can specify the 'Remote IP address' in the rule's Scope tab to allow only 192.168.1.100. All other source IP addresses are effectively denied because no matching allow rule exists, and firewall rules are evaluated in order with an implicit deny at the end unless overridden by another rule.

  • ✗

    Group Policy Management Console (gpmc.msc)

    Why it's wrong here

    Group Policy Management Console (gpmc.msc) is an enterprise utility for managing Group Policy Objects across an Active Directory domain, not a local workstation configuration tool. It is not installed by default on Windows 10 Pro, and using it to impose an IP restriction on the local firewall would require a domain environment with appropriate GPOs linking and processing. For a standalone workstation, the direct local firewall snap-in is the appropriate and straightforward method, making this option incorrect.

  • ✗

    Remote Desktop Settings in System Properties

    Why it's wrong here

    Remote Desktop Settings in System Properties (sysdm.cpl) merely toggles whether Remote Desktop is enabled and whether Network Level Authentication is required. It offers no interface for restricting incoming connections by source IP address; once Remote Desktop is enabled, any client with valid credentials can attempt a connection. IP-based access control must be implemented at the firewall layer, such as through an inbound rule in wf.msc, not in the Remote Desktop enablement dialog.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

Go deeper

Related to this question

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.