220-1102 Operating Systems Practice Question
A technician is configuring a shared Windows 10 Pro workstation that will be used by multiple employees. The company policy requires that unauthorized changes to system settings be prevented. Which built-in Windows security feature should the technician ensure is enabled?
⚠ Common exam trap
Watch out — candidates often confuse data protection features (BitLocker) or file backup utilities (File History) with system-level access control, failing to recognize that UAC is the specific mechanism designed to prevent unauthorized system setting changes in Windows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User Account Control (UAC)
User Account Control (UAC) is the built-in Windows security feature that prompts for consent or credentials before allowing actions that could affect system settings or change system state. By keeping UAC enabled, the technician ensures that any attempt to make unauthorized changes—such as installing software or modifying registry keys—requires explicit approval from an administrator, thereby enforcing the company policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
BitLocker Drive Encryption
Why it's wrong here
BitLocker Drive Encryption uses AES encryption to protect data at rest on the entire volume, safeguarding against offline data theft and unauthorized access to drive contents. However, it operates purely at the storage layer and does not interact with the Windows privilege model, so it cannot stop a logged-in user from changing system settings on a running session. It secures the data, not the system configuration, and thus does not fulfill the requirement.
- ✗
File History
Why it's wrong here
File History is a per-user backup feature that periodically copies documents, music, pictures, and other library files to an external or network drive for versioning and recovery. Since it only tracks user data files rather than the Windows registry, policy settings, or installed applications, it neither blocks nor intercepts attempts to alter system configuration. It helps restore deleted or overwritten personal files, but it is not a preventive security control for system settings.
- ✓
User Account Control (UAC)
Why this is correct
User Account Control (UAC) is the correct mechanism because it enforces the principle of least privilege by prompting for administrator consent or credentials whenever a process attempts to perform an action that changes system-wide settings. In a shared workstation, this guarantees that a standard user cannot silently modify system configuration; any such change is either blocked or requires explicit administrative approval. UAC also displays prompts on the secure desktop, preventing malware from simulating clicks, making it the appropriate preventive tool for this requirement.
- ✗
System Protection
Why it's wrong here
System Protection is a Windows feature that periodically creates restore points, which are snapshots of system files, registry settings, and certain program files used to return the system to a previous state. It is a reactive recovery tool: it does not audit, block, or require approval for changes as they occur, so it cannot prevent unwanted system modifications. Even if a restore point is later used, the harmful change still takes effect beforehand and may cause damage or security exposure.
Go deeper
Related to this question
Learn chapter
Windows User Accounts and Groups
Key term
UAC
User Account Control is a Windows security feature that prevents unauthorized changes to your computer by asking for permission before allowing certain actions.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.