Courseiva
Operating Systems →mediumMultiple Choice

220-1102 Operating Systems Practice Question

A technician needs to configure a Windows 10 workstation so that only signed drivers can be installed. Which security feature should be enabled?

⚠ Common exam trap

Test-takers frequently confuse User Account Control (UAC) with driver signing enforcement because both involve security prompts, but UAC only controls administrative elevation, not digital signature validation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Driver Signature Enforcement

Driver Signature Enforcement is the Windows security feature that ensures only drivers with a valid digital signature from a trusted publisher can be installed. When enabled, the operating system checks each driver's digital signature against a certificate authority before allowing installation, blocking unsigned or tampered drivers. This prevents potentially malicious or unstable drivers from compromising system stability and security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Driver Signature Enforcement

    Why this is correct

    Driver Signature Enforcement is the Windows 10 security mechanism that verifies a kernel-mode driver's digital signature matches a trusted certificate in the system root store before allowing installation. It prevents loading of unsigned or tampered driver files, which is crucial for system stability and security against rootkits and other malicious low-level components. Although an administrator can temporarily disable enforcement via boot options or test mode, doing so compromises the integrity of the entire operating system.

  • ✗

    Windows Defender Firewall

    Why it's wrong here

    Windows Defender Firewall is a network traffic filtering component that inspects packets based on rules for inbound and outbound connections, not file integrity or driver packages. It operates in the Windows Filtering Platform and can block or allow applications based on port, protocol, and program path, but it has no knowledge of driver signing certificates or the driver installation process. Because driver signature enforcement happens in the kernel's image loading routine, it is completely outside the firewall's scope.

  • ✗

    User Account Control

    Why it's wrong here

    User Account Control prompts for administrator consent when a process attempts to perform actions that require higher integrity levels, such as installing drivers or modifying system files. However, UAC only presents a Yes/No dialog based on the requesting process's reputation, and it does not validate the digital signature of the driver's .sys or .inf files. If a user approves the prompt, an unsigned driver can still be loaded, because UAC is an access control mechanism, not a code-integrity verification point.

  • ✗

    BitLocker

    Why it's wrong here

    BitLocker Drive Encryption uses AES-128/256-bit algorithms to encrypt the entire volume, protecting data at rest so unauthorized users cannot read the plaintext without the exact recovery key. It operates transparently at the volume level, integrating with the Trusted Platform Module to validate boot files, but it does not examine driver executables for cryptographic signatures during installation. BitLocker's purpose is confidentiality of data, not enforcing which drivers Windows will load, so it cannot substitute for Driver Signature Enforcement.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.