mediumMultiple Choice
220-1102 Practice Question: During a security audit, an administrator…
During a security audit, an administrator discovers that several employees have written their domain passwords on sticky notes attached to their monitors. The company policy requires strong passwords and prohibits sharing credentials. Which security principle is being violated?
⚠ Common exam trap
CompTIA A+ often tests the distinction between password confidentiality (keeping passwords secret) and other security controls like least privilege or MFA, leading candidates to confuse the principle of not sharing credentials with access restriction or authentication methods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Password confidentiality
Password confidentiality is the principle that passwords must be kept secret and known only to the authorized user. By writing domain passwords on sticky notes attached to monitors, employees are exposing credentials to anyone with physical access, directly violating this principle. The company policy explicitly prohibits sharing credentials, and this practice undermines the security of the domain authentication system.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Principle of least privilege
Why it's wrong here
Least privilege restricts each account to the minimum access needed for its role; it concerns authorisation scope, not how credentials are stored or concealed. It would be correct if the audit found users holding excessive permissions beyond their job duties, where trimming entitlements is the remediation.
- ✗
Account lockout policy
Why it's wrong here
Account lockout policy throttles repeated failed sign-in attempts; writing passwords on notes involves no brute-force attempts, so no lockout threshold is breached. It would be the right answer if the audit showed unlimited failed logon attempts against accounts, where configuring a lockout threshold is the fix.
- ✓
Password confidentiality
Why this is correct
Writing passwords where others can read them exposes credentials to anyone passing the workstation, breaching the requirement that authentication secrets remain known only to their owner. Confidentiality of the password itself, not its complexity, is what the sticky notes defeat.
- ✗
Multi-factor authentication
Why it's wrong here
Multi-factor authentication is an authentication control requiring a second verification factor; it does not govern password secrecy or storage, so sticky notes breach no MFA requirement. It would be the correct answer if the audit found accounts protected by passwords alone, where adding a second factor is the remediation.
Go deeper
Related to this question
Learn chapter
User Privacy Considerations
Key term
Confidentiality
Confidentiality means keeping sensitive information secret and accessible only to authorized people or systems.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.