220-1102 Operating Systems Practice Question
A technician needs to run a suspicious executable file in an isolated environment on a Windows 10 Pro workstation without using a third-party virtual machine. Which built-in Windows feature should the technician use?
⚠ Common exam trap
Many exam-takers confuse Windows Sandbox with Hyper-V, assuming both require complex setup, or they mistakenly think Windows Defender Application Guard can run any executable, when it is strictly limited to browser and document isolation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Sandbox
Windows Sandbox is a built-in Windows 10 Pro and Enterprise feature that provides a lightweight, isolated desktop environment to safely run untrusted applications without affecting the host system. It uses hardware-based virtualization to create a separate kernel instance, ensuring the executable runs in a disposable, secure sandbox that is automatically discarded upon closure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Windows Sandbox
Why this is correct
Windows Sandbox is a lightweight, ephemeral Hyper-V-based desktop environment built into Windows 10/11 Pro and Enterprise. It boots a fresh, isolated Windows instance from a clean reference image, so a suspicious executable runs inside a disposable virtualized session, and all file system, registry, and process changes are discarded the moment the sandbox closes. Because nothing persists to the host, it is purpose-built for one-off untrusted executable testing without needing to manage a VM lifecycle.
- ✗
Hyper-V
Why it's wrong here
Hyper-V enables the creation of persistent virtual machines, which retain all changes made within them. This makes it unsuitable for safely running a suspicious executable, as the environment would not automatically reset and discard potential malware modifications after use. However, Hyper-V is tempting because it is a built-in Windows virtualisation feature, designed for hosting full, isolated operating systems for development, testing, or server roles where persistence is desired, not for ephemeral sandboxing.
- ✗
Windows Defender Application Guard
Why it's wrong here
Windows Defender Application Guard isolates untrusted web content in a hardware-virtualized Microsoft Edge container, using Hyper-V to block browser-based exploits from reaching the host OS. It is not a generic application sandbox: WDAG is scoped to Edge browsing and cannot launch a standalone Windows executable from a local folder or USB drive into an isolated desktop environment. Therefore, running a suspicious .exe file falls entirely outside WDAG's intended functionality.
- ✗
Windows Subsystem for Linux
Why it's wrong here
Windows Subsystem for Linux is a compatibility and interoperability layer (WSL2 uses a lightweight utility VM) that runs native Linux ELF binaries on a real Linux kernel, but it does not provide a security boundary for Windows PE executables. When a Windows .exe is launched from within WSL, it is handed off to the host Windows process manager and executes with the current user's host privileges, able to modify the host file system, registry, and settings. WSL is a developer tool for Linux command-line workloads, not a malware containment or sandboxing mechanism.
Go deeper
Related to this question
Learn chapter
Windows Recovery Environment (WinRE)
Key term
Virtual machine
A virtual machine (VM) is a software-based emulation of a physical computer that runs an operating system and applications just like a real machine, but is isolated and managed by a hypervisor on a host system.
Key term
Windows 10
Windows 10 is a personal computer operating system developed by Microsoft that combines the familiarity of Windows 7 with the modern features of Windows 8, designed to run on a wide range of devices from desktops to tablets.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.