220-1102 Operating Systems Practice Question
A technician needs to configure a Windows 10 workstation so that a standard user can run a specific legacy application that requires administrative privileges. Company policy prohibits granting admin rights to users. What is the BEST method to accomplish this?
⚠ Common exam trap
A common mix-up: candidates confuse the 'Run this program as an administrator' compatibility setting with a method that grants elevation to standard users, when in fact it only triggers a UAC prompt that requires admin credentials to proceed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a scheduled task that runs with highest privileges and allow the user to launch it
Creating a scheduled task that runs with highest privileges allows a standard user to execute a legacy application with administrative rights without granting them admin credentials. The task runs under the SYSTEM or a specified admin account, and the user can launch it via a shortcut or script, adhering to the principle of least privilege.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the application's compatibility settings to 'Run this program as an administrator'
Why it's wrong here
The 'Run this program as an administrator' compatibility flag modifies the executable's requested execution level to require elevation. When a standard user launches it, Windows displays a UAC credential prompt requesting an administrator password; since the user lacks that credential, the launch fails. This flag neither supplies stored credentials nor bypasses UAC—it only forces the elevation prompt to appear at launch, making it unsuitable for non-administrator users.
- ✗
Use the Runas command with saved credentials
Why it's wrong here
Using 'runas /savecred' stores the administrator's password in the Windows Credential Manager, encrypted with the user's DPAPI key—but that key belongs to the standard user, so the user (or malware running in their session) can retrieve and reuse the credential. Additionally, the saved credential is not scoped to the specific application; any runas invocation can reuse it, and the user will not be prompted again. This violates the principle of least privilege and creates a reusable, extractable artifact, so it is not a secure solution.
- ✓
Create a scheduled task that runs with highest privileges and allow the user to launch it
Why this is correct
A scheduled task can be configured to run with the highest privileges (i.e., as SYSTEM or an admin account) without storing the password insecurely. The user can be granted permission to run the task (e.g., via a shortcut). This provides elevated rights safely.
- ✗
Install the application in the Program Files folder
Why it's wrong here
The installation location (e.g., Program Files) determines NTFS and UAC virtualization scope, but it does not change the application's effective requested execution level. An application with a requireAdministrator manifest or one that writes to protected registry keys or folders will still trigger a UAC elevation prompt when run by a standard user, regardless of its directory. Only modifying the executable's manifest (or using a mechanism like a scheduled task) can alter the elevation behavior; file placement alone is irrelevant.
Go deeper
Related to this question
Learn chapter
User Account Control (UAC)
Key term
Windows 10
Windows 10 is a personal computer operating system developed by Microsoft that combines the familiarity of Windows 7 with the modern features of Windows 8, designed to run on a wide range of devices from desktops to tablets.
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.