220-1102 Operating Systems Practice Question
A technician needs to prevent a standard user on a Windows 10 computer from installing unauthorized software without providing an administrator password. The user already has a standard user account. Which tool should the technician use to enforce this restriction?
⚠ Common exam trap
Many candidates confuse UAC with Group Policy-based restrictions like AppLocker or software restriction policies, thinking those tools also enforce password prompts, when in fact UAC is the specific mechanism that triggers the credential dialog for standard users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure User Account Control (UAC) settings
User Account Control (UAC) is the built-in Windows security feature that prompts for consent or credentials when a standard user attempts to perform an action that requires administrative privileges. By default, UAC is configured to notify standard users and require an administrator password before allowing software installations, effectively preventing unauthorized installations without the admin password.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure User Account Control (UAC) settings
Why this is correct
UAC is the built-in security component that prompts for administrator credentials whenever a standard user attempts an action requiring elevation, such as a system-wide software installation. Because the user's token is filtered, the Windows Installer service is blocked from making system-level changes until an administrator password is entered into the UAC consent prompt. This is the most direct and native way to gate installation, and setting the 'Admin Approval Mode' or 'Prompt on secure desktop' further strengthens the control.
- ✗
Use Local Group Policy Editor to set software restriction policies
Why it's wrong here
Software Restriction Policies (SRP) allow you to define rules that prevent specific executables, scripts, or MSI packages from running, either by hash, path, zone, or certificate. However, SRP does not itself present a UAC-style credential prompt; it simply blocks execution, which can be bypassed by a determined user and may require careful rule maintenance. While it can be part of a broader security policy, it is not the most direct way to control who can approve an installation — UAC natively handles that elevation consent.
- ✗
Use System Configuration (msconfig) to disable installation services
Why it's wrong here
The System Configuration utility (msconfig) manages boot options, startup items, and Windows services, but it does not enforce user permission decisions. Disabling the Windows Installer service from msconfig would require administrative rights, would break all MSI-based installations system-wide, and would affect all users rather than just standard users. This is a drastic and nonpermissive approach that doesn't provide per-user approval control, so it's not the correct answer.
- ✗
Configure Credential Manager to require administrative credentials
Why it's wrong here
Credential Manager is a Windows vault that stores username/password pairs for network shares, websites, and other resources, and it can manage generic credentials for applications. It does not intercept or filter software installation attempts, and there is no setting to 'require administrative credentials' for installations. Even if an admin stored a password in Credential Manager, the standard user would not be prompted to use that password for elevation, so this option is unrelated to installation permissions.
Go deeper
Related to this question
Learn chapter
User Account Control (UAC)
Key term
User Account Control
User Account Control (UAC) is a Windows security feature that prevents unauthorized changes to the operating system by prompting for permission before allowing actions that affect system settings or installed programs.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.