220-1102 Security Practice Question
A technician is configuring a new Windows 10 Pro workstation that is not part of a domain. The company's security policy requires that user passwords must be at least 8 characters and expire every 90 days. Which built-in tool should the technician use to enforce these requirements on this local workstation?
⚠ Common exam trap
It's easy for candidates to confuse the User Accounts control panel (which handles individual account settings) with the Local Security Policy (which enforces system-wide security policies), especially since both are accessible from the Control Panel or Administrative Tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Local Security Policy
The Local Security Policy (secpol.msc) is the built-in tool for configuring password policies, including minimum password length and maximum password age, on a standalone Windows 10 Pro workstation that is not part of a domain. These settings are stored in the local Security Accounts Manager (SAM) database and enforced by the Local Security Authority (LSA).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Local Security Policy
Why this is correct
secpol.msc is an MMC snap-in that provides direct access to Account Policies stored in the local Security Accounts Manager (SAM). Under Security Settings > Account Policies, administrators can set password complexity, minimum/maximum password age, password history length, and account lockout thresholds. These policy settings are enforced by the Local Security Authority (LSA) during local logon authentication, making them the correct tool for a standalone Windows 10 Pro workstation not joined to a domain.
- ✗
User Accounts control panel
Why it's wrong here
The User Accounts Control Panel applet is a user-friendly interface for creating user accounts, changing passwords, and modifying account type, but it is purely a management UI. It has no interface for configuring password complexity requirements, password expiration, or lockout thresholds — those rules are enforced independently by the operating system after being set in Local Security Policy. At best, it lets individual users comply with an existing password policy when changing their own password, but it cannot define or modify the policy itself.
- ✗
Group Policy Management Console (GPMC)
Why it's wrong here
Group Policy Management Console is designed exclusively for managing Group Policy Objects in an Active Directory domain environment; it connects to domain controllers and relies on the AD logical structure of sites, domains, and OUs. A standalone Windows 10 Pro workstation has no domain and thus no domain controllers or GPOs to link, and GPMC cannot be used to edit local policy. The local equivalent for this task is either secpol.msc or the Local Group Policy Editor (gpedit.msc) — GPMC would be relevant only after the machine is domain-joined.
- ✗
Credential Manager
Why it's wrong here
Credential Manager functions as a secure vault that persists user credentials such as saved website logins, Windows network share passwords, and cached domain credentials, so users don't have to re-enter them. It has no relationship to password policy enforcement and offers no settings for password age, complexity, or account lockout. In fact, Credential Manager can actually store credentials that are more permissive than the local policy, because it is only a storage mechanism for existing authentication tokens and password data.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Windows 10
Windows 10 is a personal computer operating system developed by Microsoft that combines the familiarity of Windows 7 with the modern features of Windows 8, designed to run on a wide range of devices from desktops to tablets.
Key term
Security policy
A security policy is a formal set of rules and guidelines that an organization establishes to protect its information assets and technology resources.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.