220-1102 Operating Systems Practice Question
A technician needs to configure a Windows 10 workstation so that only signed drivers can be installed. Which security feature should be enabled?
⚠ Common exam trap
Test-takers frequently confuse User Account Control (UAC) with driver signing enforcement because both involve security prompts, but UAC only controls administrative elevation, not digital signature validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Driver Signature Enforcement
Driver Signature Enforcement is the Windows security feature that ensures only drivers with a valid digital signature from a trusted publisher can be installed. When enabled, the operating system checks each driver's digital signature against a certificate authority before allowing installation, blocking unsigned or tampered drivers. This prevents potentially malicious or unstable drivers from compromising system stability and security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Driver Signature Enforcement
Why this is correct
Driver Signature Enforcement is the Windows 10 security mechanism that verifies a kernel-mode driver's digital signature matches a trusted certificate in the system root store before allowing installation. It prevents loading of unsigned or tampered driver files, which is crucial for system stability and security against rootkits and other malicious low-level components. Although an administrator can temporarily disable enforcement via boot options or test mode, doing so compromises the integrity of the entire operating system.
- ✗
Windows Defender Firewall
Why it's wrong here
Windows Defender Firewall is a network traffic filtering component that inspects packets based on rules for inbound and outbound connections, not file integrity or driver packages. It operates in the Windows Filtering Platform and can block or allow applications based on port, protocol, and program path, but it has no knowledge of driver signing certificates or the driver installation process. Because driver signature enforcement happens in the kernel's image loading routine, it is completely outside the firewall's scope.
- ✗
User Account Control
Why it's wrong here
User Account Control prompts for administrator consent when a process attempts to perform actions that require higher integrity levels, such as installing drivers or modifying system files. However, UAC only presents a Yes/No dialog based on the requesting process's reputation, and it does not validate the digital signature of the driver's .sys or .inf files. If a user approves the prompt, an unsigned driver can still be loaded, because UAC is an access control mechanism, not a code-integrity verification point.
- ✗
BitLocker
Why it's wrong here
BitLocker Drive Encryption uses AES-128/256-bit algorithms to encrypt the entire volume, protecting data at rest so unauthorized users cannot read the plaintext without the exact recovery key. It operates transparently at the volume level, integrating with the Trusted Platform Module to validate boot files, but it does not examine driver executables for cryptographic signatures during installation. BitLocker's purpose is confidentiality of data, not enforcing which drivers Windows will load, so it cannot substitute for Driver Signature Enforcement.
Go deeper
Related to this question
Learn chapter
Linux File System Structure
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.