mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: During a security audit, you discover that a…
During a security audit, you discover that a user’s Windows 10 device has allowed multiple failed login attempts without locking the account. Which policy should you adjust to enforce account lockout after 5 failed attempts?
⚠ Common exam trap
The CompTIA A+ exam often tests the distinction between password policy settings (which govern password complexity and length) and account lockout policy settings (which govern failed attempt limits), leading candidates to mistakenly choose Password Policy options when the question is about lockout enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Account Lockout Policy – Account lockout threshold
The Account Lockout Policy – Account lockout threshold setting directly controls the number of failed logon attempts allowed before the account is locked. By setting this value to 5, the system will enforce a lockout after exactly five incorrect password entries, preventing further brute-force attempts until an administrator unlocks the account or the lockout duration expires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password Policy – Minimum password length
Why it's wrong here
This setting dictates the fewest characters a user's password can contain, directly impacting password strength and resistance to brute-force attacks. While crucial for overall security, it does not govern the number of incorrect login attempts allowed before an account is temporarily disabled. Therefore, adjusting minimum password length would not address a user's account locking out due to too many failed login attempts.
- ✓
Account Lockout Policy – Account lockout threshold
Why this is correct
The Account lockout threshold policy directly specifies the maximum number of consecutive unsuccessful login attempts permitted before a user account is automatically locked out. Once this threshold is met, the system prevents further login attempts for that account, typically for a defined duration or until an administrator intervenes. This policy is precisely designed to mitigate brute-force attacks by preventing an attacker from making unlimited login attempts.
- ✗
User Rights Assignment – Deny log on locally
Why it's wrong here
The "Deny log on locally" user right assignment explicitly prevents specified users or groups from initiating an interactive logon session directly at the computer console. This security setting is used to restrict access to the physical machine itself, ensuring only authorized personnel can log on. It does not, however, regulate the number of failed login attempts an account can endure before being locked out; it's about permission to log on at all, not the conditions for lockout.
- ✗
Security Options – Interactive logon: Message text for users attempting to log on
Why it's wrong here
The "Interactive logon: Message text for users attempting to log on" security option is used to display a custom message or legal notice to users before they are presented with the login prompt. This serves as a banner or disclaimer, informing users of policies or monitoring. While important for compliance and user awareness, this setting is purely informational and has no functional role in enforcing account security mechanisms like password complexity, lockout thresholds, or the number of allowed failed login attempts.
Go deeper
Related to this question
Learn chapter
Windows Editions and Features
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.