Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A technician is supporting a field engineer tablet. The immediate goal is to grant users only the access needed for their job. Which tool, control, or procedure is the best fit?

⚠ Common exam trap

Candidates often confuse the tool used to implement a principle (Local Users and Groups) with the principle itself (least privilege), leading them to select a concrete tool rather than the overarching security control that best fits the goal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

least privilege

The principle of least privilege dictates that users should be granted only the permissions necessary to perform their job functions, minimizing security risks. For a field engineer tablet, this means configuring user accounts with restricted access to specific applications, files, and system settings, rather than administrative rights. This directly aligns with the goal of limiting access to what is needed, making least privilege the correct security control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    least privilege

    Why this is correct

    Least privilege grants each user only the permissions their role requires, directly satisfying the goal of limiting access to job needs. Applied through account groups and file-share permissions, it minimises attack surface and prevents lateral movement from compromised accounts on the shared field tablet.

  • ✗

    Event Viewer

    Why it's wrong here

    Event Viewer only records system, application and security log entries; it cannot assign or restrict permissions. It is tempting because security auditing appears there, and it would be the right tool for investigating logon failures or tracing why an access attempt was denied.

  • ✗

    System Restore

    Why it's wrong here

    System Restore reverts Windows system files, drivers and registry settings to an earlier restore point; it does not manage user permissions. It is tempting as a quick recovery measure, and would be correct for rolling back a faulty driver or application update on the tablet.

  • ✗

    Local Users and Groups

    Why it's wrong here

    Local Users and Groups manages accounts on a single Windows machine, so it cannot scope access by job role across a domain. It is tempting because it does control local account membership, and would suffice for a standalone, non-domain workstation where per-machine permissions are all that matter.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.