220-1102 Security Practice Question
A technician is supporting a remote worker laptop. The immediate goal is to slow repeated password guessing. Which tool, control, or procedure is the best fit?
⚠ Common exam trap
Many candidates confuse Event Viewer (A) as a proactive control because it can show failed logins, but it is only a monitoring tool, not a preventive measure against password guessing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
account lockout policy
The account lockout policy (C) is the best fit because it directly mitigates repeated password guessing by locking the account after a configurable number of failed attempts (e.g., 3–5). This is a standard security control in Windows Group Policy or Local Security Policy that thwarts brute-force attacks without requiring additional software or manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Event Viewer
Why it's wrong here
Event Viewer is a diagnostic logging tool that records security and system events after they occur, making it useful for reviewing past login attempts or identifying the source of an attack. However, it does not actively slow or block authentication failures, as it only provides a passive audit trail. Therefore, while helpful for post-incident analysis, it cannot serve as the primary control for mitigating a brute-force or credential-stuffing attack in real time.
- ✗
System Restore
Why it's wrong here
System Restore is a recovery feature that reverts Windows system files, registry settings, and installed programs to a previous snapshot, often used to undo harmful changes or corruptions. It does not influence the operating system's login authentication behavior or throttling mechanisms, so it cannot slow repeated failed login attempts. Moreover, initiating a restore would disrupt the remote worker's system rather than impose a security control, making it unsuitable for the stated objective.
- ✓
account lockout policy
Why this is correct
Account lockout policy is a Windows security policy that defines the maximum number of invalid logon attempts permitted before the system locks the account, typically followed by a lockout duration. By implementing a low threshold, an administrator can effectively slow down brute-force password guessing because each batch of failures triggers a temporary or indefinite lockout, denying further attempts. This directly reduces the attacker's speed and success rate, making it the correct control for the stated goal.
- ✗
Local Users and Groups
Why it's wrong here
Local Users and Groups is an administrative snap-in used to create, disable, or manage user accounts and group memberships on a standalone system. While an administrator could manually disable an account after an attack, this tool does not provide automated thresholds or timed lockout behaviors, leaving no mechanism to slow repeated failed logins dynamically. It lacks the policy-driven enforcement needed to mitigate ongoing brute-force attempts, so it is not the right solution for the scenario.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
Key term
Security control
A security control is a safeguard or countermeasure designed to protect the confidentiality, integrity, and availability of information systems and data.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A technician is supporting a shared training-room workstation. The immediate goal is to slow repeated password guessing. Which tool, control, or procedure is the best fit?
medium- A.Local Users and Groups
- B.Event Viewer
- C.System Restore
- ✓ D.account lockout policy
Why D: The account lockout policy is the best fit because it directly mitigates repeated password guessing by locking the account after a specified number of failed attempts. This is a security control configured via Group Policy or Local Security Policy, and it is the standard defense against brute-force attacks on Windows workstations.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.