Courseiva
Operating Systems →mediumMultiple Choice

220-1102 Operating Systems Practice Question

A technician needs to ensure that all domain-joined Windows 10 computers in the company automatically install approved updates from a local Windows Server Update Services (WSUS) server instead of downloading them from Microsoft's update servers. Which configuration method should the technician use?

⚠ Common exam trap

Many candidates confuse Local Security Policy with Group Policy, thinking that local settings can scale to a domain, or they assume manual registry edits are a valid enterprise solution, overlooking the centralized management and enforcement that Group Policy provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply a Group Policy Object (GPO) that specifies the intranet update service location.

Group Policy Objects (GPOs) provide centralized configuration for domain-joined computers. By configuring the 'Specify intranet Microsoft update service location' policy under Computer Configuration > Administrative Templates > Windows Components > Windows Update, the technician can point all workstations to the local WSUS server, ensuring automatic approval and installation of updates without contacting Microsoft's servers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Modify the Windows Update settings in the Control Panel on each workstation.

    Why it's wrong here

    Modifying Windows Update settings through the Control Panel on each machine only alters local client configuration. On domain-joined computers, any Group Policy-driven Windows Update settings, including the WSUS intranet server, override these local selections. This approach is not only unenforceable and user-modifiable, but it also fails to provide a centralized, consistent configuration across the entire fleet.

  • ✗

    Configure the WSUS client via the Registry Editor on each workstation.

    Why it's wrong here

    While you can manually set the WUServer and WUStatusServer registry values under HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate, editing each workstation's registry independently is error-prone, unscalable, and does not guarantee consistent configuration. Moreover, if a WSUS-related Group Policy Object is applied later, the policy will overwrite these manual registry entries, making the effort redundant and unreliable for domain-wide management.

  • ✓

    Apply a Group Policy Object (GPO) that specifies the intranet update service location.

    Why this is correct

    The correct solution is to deploy a Group Policy Object (GPO) configured with the 'Specify intranet Microsoft update service location' setting under Administrative Templates > Windows Components > Windows Update. This policy centrally defines the WSUS server URLs, and the client side enforces it on all domain-joined Windows 10 computers during policy refresh. Because Group Policy takes precedence over local settings, applying one GPO to an OU ensures every affected machine consistently uses WSUS without per-machine intervention.

  • ✗

    Use the Local Security Policy on each computer to set the update source.

    Why it's wrong here

    Local Security Policy (secpol.msc) manages security-configuration settings such as account policies, user rights assignment, Windows Defender Firewall, and software restriction policies. Windows Update's WSUS server location is not exposed in the Local Security Policy editor; it lives under Administrative Templates, which is a Group Policy-only feature. Even if you applied local policies per computer, they would be overridden by any domain GPO and provide no central management.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1102

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A technician needs to configure a Windows 10 Pro workstation to retrieve updates from a local WSUS server instead of directly from Microsoft Update. Which tool should the technician use to configure this setting?

medium
  • ✓ A.Group Policy Editor
  • B.Windows Update Settings
  • C.Local Security Policy
  • D.System Configuration

Why A: The Group Policy Editor (gpedit.msc) is the correct tool because it allows the technician to configure the 'Specify intranet Microsoft update service location' policy under Computer Configuration > Administrative Templates > Windows Components > Windows Update. This policy sets the WSUS server as the update source by specifying both the intranet update service and the statistics server URLs, overriding the default Microsoft Update connection.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.