Courseiva
Operating Systems →mediumMultiple Choice

220-1102 Operating Systems Practice Question

A technician needs to prevent a standard user on a Windows 10 computer from installing unauthorized software without providing an administrator password. The user already has a standard user account. Which tool should the technician use to enforce this restriction?

⚠ Common exam trap

Many candidates confuse UAC with Group Policy-based restrictions like AppLocker or software restriction policies, thinking those tools also enforce password prompts, when in fact UAC is the specific mechanism that triggers the credential dialog for standard users.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure User Account Control (UAC) settings

User Account Control (UAC) is the built-in Windows security feature that prompts for consent or credentials when a standard user attempts to perform an action that requires administrative privileges. By default, UAC is configured to notify standard users and require an administrator password before allowing software installations, effectively preventing unauthorized installations without the admin password.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure User Account Control (UAC) settings

    Why this is correct

    UAC is the built-in security component that prompts for administrator credentials whenever a standard user attempts an action requiring elevation, such as a system-wide software installation. Because the user's token is filtered, the Windows Installer service is blocked from making system-level changes until an administrator password is entered into the UAC consent prompt. This is the most direct and native way to gate installation, and setting the 'Admin Approval Mode' or 'Prompt on secure desktop' further strengthens the control.

  • ✗

    Use Local Group Policy Editor to set software restriction policies

    Why it's wrong here

    Software Restriction Policies (SRP) allow you to define rules that prevent specific executables, scripts, or MSI packages from running, either by hash, path, zone, or certificate. However, SRP does not itself present a UAC-style credential prompt; it simply blocks execution, which can be bypassed by a determined user and may require careful rule maintenance. While it can be part of a broader security policy, it is not the most direct way to control who can approve an installation — UAC natively handles that elevation consent.

  • ✗

    Use System Configuration (msconfig) to disable installation services

    Why it's wrong here

    The System Configuration utility (msconfig) manages boot options, startup items, and Windows services, but it does not enforce user permission decisions. Disabling the Windows Installer service from msconfig would require administrative rights, would break all MSI-based installations system-wide, and would affect all users rather than just standard users. This is a drastic and nonpermissive approach that doesn't provide per-user approval control, so it's not the correct answer.

  • ✗

    Configure Credential Manager to require administrative credentials

    Why it's wrong here

    Credential Manager is a Windows vault that stores username/password pairs for network shares, websites, and other resources, and it can manage generic credentials for applications. It does not intercept or filter software installation attempts, and there is no setting to 'require administrative credentials' for installations. Even if an admin stored a password in Credential Manager, the standard user would not be prompted to use that password for elevation, so this option is unrelated to installation permissions.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.