Courseiva
mediumMultiple ChoiceObjective-mapped

220-1102 Practice Question: During a security audit, you discover that a…

During a security audit, you discover that a user’s Windows 10 device has allowed multiple failed login attempts without locking the account. Which policy should you adjust to enforce account lockout after 5 failed attempts?

⚠ Common exam trap

The CompTIA A+ exam often tests the distinction between password policy settings (which govern password complexity and length) and account lockout policy settings (which govern failed attempt limits), leading candidates to mistakenly choose Password Policy options when the question is about lockout enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Account Lockout Policy – Account lockout threshold

The Account Lockout Policy – Account lockout threshold setting directly controls the number of failed logon attempts allowed before the account is locked. By setting this value to 5, the system will enforce a lockout after exactly five incorrect password entries, preventing further brute-force attempts until an administrator unlocks the account or the lockout duration expires.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Password Policy – Minimum password length

    Why it's wrong here

    This setting dictates the fewest characters a user's password can contain, directly impacting password strength and resistance to brute-force attacks. While crucial for overall security, it does not govern the number of incorrect login attempts allowed before an account is temporarily disabled. Therefore, adjusting minimum password length would not address a user's account locking out due to too many failed login attempts.

  • Account Lockout Policy – Account lockout threshold

    Why this is correct

    The Account lockout threshold policy directly specifies the maximum number of consecutive unsuccessful login attempts permitted before a user account is automatically locked out. Once this threshold is met, the system prevents further login attempts for that account, typically for a defined duration or until an administrator intervenes. This policy is precisely designed to mitigate brute-force attacks by preventing an attacker from making unlimited login attempts.

  • User Rights Assignment – Deny log on locally

    Why it's wrong here

    The "Deny log on locally" user right assignment explicitly prevents specified users or groups from initiating an interactive logon session directly at the computer console. This security setting is used to restrict access to the physical machine itself, ensuring only authorized personnel can log on. It does not, however, regulate the number of failed login attempts an account can endure before being locked out; it's about permission to log on at all, not the conditions for lockout.

  • Security Options – Interactive logon: Message text for users attempting to log on

    Why it's wrong here

    The "Interactive logon: Message text for users attempting to log on" security option is used to display a custom message or legal notice to users before they are presented with the login prompt. This serves as a banner or disclaimer, informing users of policies or monitoring. While important for compliance and user awareness, this setting is purely informational and has no functional role in enforcing account security mechanisms like password complexity, lockout thresholds, or the number of allowed failed login attempts.

About these practice questions

One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.