220-1102 Security Practice Question
A technician is supporting a shared training-room workstation. The immediate goal is to slow repeated password guessing. Which tool, control, or procedure is the best fit?
⚠ Common exam trap
Candidates often confuse Event Viewer (logging) with active prevention, or think Local Users and Groups can enforce lockout settings, when in fact only the account lockout policy directly controls the lockout behavior.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
account lockout policy
The account lockout policy is the best fit because it directly mitigates repeated password guessing by locking the account after a specified number of failed attempts. This is a security control configured via Group Policy or Local Security Policy, and it is the standard defense against brute-force attacks on Windows workstations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Local Users and Groups
Why it's wrong here
Local Users and Groups manages accounts and group membership, but it does not itself enforce lockout thresholds or logon delays. It is the correct place to configure account lockout policy, yet the tool alone does not slow repeated password guessing.
- ✗
Event Viewer
Why it's wrong here
Event Viewer only records and displays logged events; it applies no control that delays or locks out repeated authentication attempts. It is the right tool for investigating which account was targeted after an incident, not for slowing guessing as it happens.
- ✗
System Restore
Why it's wrong here
System Restore reverts Windows system files and registry settings to an earlier restore point; it has no authentication component and cannot throttle or lock out logon attempts. It is intended for recovering a workstation after a faulty driver or update.
- ✓
account lockout policy
Why this is correct
An account lockout policy locks the account after a set number of failed sign-in attempts, directly slowing repeated password guessing on the shared workstation. It is the targeted control for brute-force attempts, unlike password complexity or screen locks, which do not throttle guessing.
Go deeper
Related to this question
Learn chapter
Account Lockout Policies
Key term
Security control
A security control is a safeguard or countermeasure designed to protect the confidentiality, integrity, and availability of information systems and data.
Key term
Security policy
A security policy is a formal set of rules and guidelines that an organization establishes to protect its information assets and technology resources.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.