Courseiva
mediumMultiple Choice

220-1102 Practice Question: During a security audit, an administrator…

During a security audit, an administrator discovers that several employees have written their domain passwords on sticky notes attached to their monitors. The company policy requires strong passwords and prohibits sharing credentials. Which security principle is being violated?

⚠ Common exam trap

CompTIA A+ often tests the distinction between password confidentiality (keeping passwords secret) and other security controls like least privilege or MFA, leading candidates to confuse the principle of not sharing credentials with access restriction or authentication methods.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Password confidentiality

Password confidentiality is the principle that passwords must be kept secret and known only to the authorized user. By writing domain passwords on sticky notes attached to monitors, employees are exposing credentials to anyone with physical access, directly violating this principle. The company policy explicitly prohibits sharing credentials, and this practice undermines the security of the domain authentication system.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Principle of least privilege

    Why it's wrong here

    Least privilege restricts each account to the minimum access needed for its role; it concerns authorisation scope, not how credentials are stored or concealed. It would be correct if the audit found users holding excessive permissions beyond their job duties, where trimming entitlements is the remediation.

  • ✗

    Account lockout policy

    Why it's wrong here

    Account lockout policy throttles repeated failed sign-in attempts; writing passwords on notes involves no brute-force attempts, so no lockout threshold is breached. It would be the right answer if the audit showed unlimited failed logon attempts against accounts, where configuring a lockout threshold is the fix.

  • ✓

    Password confidentiality

    Why this is correct

    Writing passwords where others can read them exposes credentials to anyone passing the workstation, breaching the requirement that authentication secrets remain known only to their owner. Confidentiality of the password itself, not its complexity, is what the sticky notes defeat.

  • ✗

    Multi-factor authentication

    Why it's wrong here

    Multi-factor authentication is an authentication control requiring a second verification factor; it does not govern password secrecy or storage, so sticky notes breach no MFA requirement. It would be the correct answer if the audit found accounts protected by passwords alone, where adding a second factor is the remediation.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.