220-1102 Operating Systems Practice Question
A technician needs to configure a Windows 10 workstation so that a specific legacy application always runs with administrator privileges without prompting for credentials. The user is a standard user. Which of the following methods will achieve this with the LEAST security risk?
⚠ Common exam trap
Many exam-takers choose Option A (giving the user local admin rights) because it seems simplest, but they overlook that Task Scheduler can achieve the same goal with far less security risk by limiting elevation to a single application.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Task Scheduler to run the application with highest privileges
Task Scheduler can be configured to run a task with the highest privileges (i.e., the local SYSTEM account or a specified administrator account) without requiring the user to enter credentials. The task can be triggered by the user launching the application (e.g., via a shortcut that runs the task), and since the task runs with stored credentials, the standard user is not prompted. This method minimizes security risk by not granting the user permanent administrative rights and by limiting elevation to only the specific application.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Give the user local administrator rights
Why it's wrong here
Granting local administrator rights changes the security context of the entire user session, not just the legacy application. Every process the user launches—including web browsers, email clients, and potentially malicious scripts—runs with full administrative privileges, which can allow malware to modify system files, disable protections, or access other users' data. This violates the principle of least privilege and unnecessarily expands the attack surface. It is a blunt, system-wide solution rather than a targeted elevation for one legacy program.
- ✓
Use Task Scheduler to run the application with highest privileges
Why this is correct
Task Scheduler can create a task that launches the legacy application with the 'Run with highest privileges' option, using stored administrative credentials (ideally a dedicated service account) without exposing the password to the user. The task runs the executable in the user's interactive session but with an elevated token, so the application sees an admin context while the user's own account remains a standard user. This scopes elevated rights to only that specific process tree, minimizes risk, and can be automated to run at logon or via a desktop shortcut.
- ✗
Instruct the user to use 'Run as different user' and enter admin credentials
Why it's wrong here
Using 'Run as different user' requires the user to know and manually type the administrative password each time the application is launched. This exposes the credentials to shoulder-surfing, keylogging, or accidental disclosure, and the credentials may become cached in the Credential Manager. It also places an administrative password in the hands of a standard user, which increases the risk of unauthorized elevation or credential theft. The process is manual, error-prone, and not a least-privilege solution for repeated legacy app use.
- ✗
Store admin credentials in a batch file using the 'Runas' command
Why it's wrong here
Storing admin credentials in a batch file with the 'Runas' command is inherently insecure because plaintext passwords can be read by any user with access to the file system. Even if the password is obfuscated or using /savecred, any user who can execute the script can launch the application with elevated privileges, effectively granting administrator access to anyone who finds the script. Additionally, the batch file could be tampered with to run arbitrary malicious commands with elevated rights. This approach fails to protect the admin credentials and is far riskier than a properly configured scheduled task.
Go deeper
Related to this question
Learn chapter
Windows User Accounts and Groups
Key term
Windows 10
Windows 10 is a personal computer operating system developed by Microsoft that combines the familiarity of Windows 7 with the modern features of Windows 8, designed to run on a wide range of devices from desktops to tablets.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A technician needs to configure a Windows 10 workstation so that a standard user can run a specific legacy application that requires administrative privileges. Company policy prohibits granting admin rights to users. What is the BEST method to accomplish this?
medium- A.Configure the application's compatibility settings to 'Run this program as an administrator'
- B.Use the Runas command with saved credentials
- ✓ C.Create a scheduled task that runs with highest privileges and allow the user to launch it
- D.Install the application in the Program Files folder
Why C: Creating a scheduled task that runs with highest privileges allows a standard user to execute a legacy application with administrative rights without granting them admin credentials. The task runs under the SYSTEM or a specified admin account, and the user can launch it via a shortcut or script, adhering to the principle of least privilege.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.