mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: During a security audit, you find that a user's…
During a security audit, you find that a user's workstation has a USB device that automatically logs in to a cloud storage account when inserted. What security best practice is being violated?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disabling auto-run
USB auto-run devices can bypass authentication and pose a security risk. Disabling auto-run prevents unauthorized access and malware from executing automatically, which is a key security practice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password complexity requirements
Why it's wrong here
Password complexity requirements dictate the minimum length, character types (uppercase, lowercase, numbers, symbols), and history of user passwords. While crucial for preventing brute-force attacks and dictionary attacks against user accounts, these policies do not prevent a system from automatically executing code or logging in via a USB device upon insertion. They focus solely on the strength of authentication credentials, not on device interaction behaviors.
- ✗
Account lockout policies
Why it's wrong here
Account lockout policies are designed to thwart brute-force password guessing attempts by temporarily disabling an account after a specified number of failed login attempts. This security measure protects against unauthorized access through repeated credential trials. However, it has no bearing on whether a USB device can trigger an automatic login process or execute malicious code upon connection, as such actions bypass the standard login prompt that account lockout policies monitor.
- ✓
Disabling auto-run
Why this is correct
Disabling auto-run (or auto-play) prevents removable media, such as USB drives, from automatically executing pre-configured actions or launching programs when connected to a system. This critical security control stops malicious scripts or executables embedded on a USB device from running without user intervention, effectively mitigating the risk of automatic logins or malware infection initiated by simply plugging in a compromised drive. It directly addresses the automatic execution behavior.
- ✗
Enforcing screen locks
Why it's wrong here
Enforcing screen locks automatically secures a workstation after a period of inactivity or when manually invoked, requiring a password to regain access. This measure is vital for protecting data from unauthorized viewing or manipulation when a user steps away from their computer. However, a screen lock only prevents interactive access to the desktop; it does not prevent the operating system from detecting and potentially auto-running content from a newly inserted USB device, which can occur even at the locked screen.
Go deeper
Related to this question
Learn chapter
Malware Types and Removal
Key term
Cloud storage
Cloud storage is a service that lets you save data on remote servers accessed over the internet instead of on your computer's hard drive.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.