Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A security administrator wants to prevent users from running unauthorized portable applications (e.g., a portable web browser on a USB drive) on their Windows 10 workstations. Which security policy implementation would be MOST effective?

⚠ Common exam trap

Candidates often confuse data-at-rest encryption (BitLocker To Go) with execution control (AppLocker), leading candidates to choose an encryption solution when the question specifically asks about preventing application execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement AppLocker rules to block execution from removable drives

AppLocker is a Windows security feature that allows administrators to create rules controlling which applications can run on a system. By configuring AppLocker rules to block execution from removable drives, the administrator can prevent users from launching unauthorized portable applications, such as a portable web browser stored on a USB drive. This directly addresses the threat of running unapproved software from external media.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement AppLocker rules to block execution from removable drives

    Why this is correct

    AppLocker uses executable rules (e.g., path, publisher, file hash) to enforce application control. By creating a deny rule targeting the 'Removable Drives' path condition, AppLocker blocks the launch of portable executables directly from USB or other removable media, even if the user has local administrator rights, because AppLocker's policy is enforced by the Application Identity service at process creation. This is a preventive control that addresses the core behavior of running unauthorized portable apps, unlike the other options that only mitigate indirect aspects.

  • ✗

    Enable BitLocker To Go on all USB drives

    Why it's wrong here

    BitLocker To Go provides full-volume encryption for removable drives, ensuring that data on the USB drive is confidential and cannot be read without the correct recovery key or password. However, encryption does not alter the operating system's execution policy: once the drive is unlocked, Windows treats it like any other writable volume, and portable executables on it can still be launched normally by the user. Therefore, BitLocker To Go protects data at rest but has zero effect on preventing unauthorized application execution from that drive.

  • ✗

    Disable the Autorun feature via Group Policy

    Why it's wrong here

    Disabling AutoRun via Group Policy (e.g., setting 'Turn off AutoPlay' or 'No autorun' policy) stops the automatic launch of programs or scripts when the USB drive is inserted, which can block one specific malware distribution vector. But AutoRun is a convenience feature—it does not restrict manual execution. A user can simply navigate to the drive in File Explorer and double-click a portable executable, which the OS will run normally because no application whitelisting or execution-blocking mechanism is in place.

  • ✗

    Set User Account Control (UAC) to always notify

    Why it's wrong here

    UAC's 'Always notify' setting forces a consent prompt when a program tries to perform an action requiring administrator privileges, but it does not evaluate or block the program's execution itself. Most portable applications are user-mode executables that run under the user's standard or admin token without triggering elevation, so they launch without any UAC prompt. Additionally, if the user is already the administrator and the app is flagged as requiring elevation, UAC only asks for confirmation—it does not function as an application blacklist or policy-based execution control.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.