220-1102 Security Practice Question
A technician is supporting a warehouse desktop. The immediate goal is to grant users only the access needed for their job. Which tool, control, or procedure is the best fit?
⚠ Common exam trap
Watch out — candidates often confuse the tool used to implement a security concept (Local Users and Groups) with the concept itself (least privilege), leading them to select the tool rather than the principle that best fits the stated goal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
least privilege
The principle of least privilege dictates that users should be granted only the permissions necessary to perform their job functions. This directly addresses the goal of restricting access on the warehouse desktop. Implementing least privilege minimizes the attack surface and reduces the risk of accidental or malicious data modification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
System Restore
Why it's wrong here
System Restore reverts system files, drivers and registry settings to an earlier restore point; it has no mechanism for assigning or limiting user permissions. It is tempting because it is a familiar recovery tool, and would be the right choice when a bad driver or update has broken the desktop and rollback is needed.
- ✗
Local Users and Groups
Why it's wrong here
Local Users and Groups creates and manages accounts on the local machine, but it does not scope a user's rights to only their job tasks; permissions come from group membership and NTFS/share ACLs. It is tempting because it is the standard console for local account administration, and would be correct when creating or resetting a standalone workstation account.
- ✓
least privilege
Why this is correct
The principle of least privilege restricts user accounts to only the permissions necessary for their specific warehouse role, such as inventory scanning or shipping, rather than granting broad administrative rights. This directly satisfies the stem’s constraint of granting “only the access needed for their job,” minimising the attack surface and preventing accidental or malicious changes to the desktop’s operating system or shared data.
- ✗
Event Viewer
Why it's wrong here
Event Viewer only records system, application and security events for auditing and diagnosis; it cannot assign or restrict permissions. It is tempting because security logs reveal access attempts, so it suits investigating suspicious activity or troubleshooting failures, not enforcing least privilege for warehouse users.
Go deeper
Related to this question
Learn chapter
Data Sanitization: Wipe, Degauss, Shred, Incinerate
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.