Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A technician is supporting a warehouse desktop. The immediate goal is to protect unattended workstations. Which tool, control, or procedure is the best fit?

⚠ Common exam trap

Many candidates confuse a reactive or administrative tool (like Event Viewer or Local Users and Groups) with a proactive security control, or they mistake System Restore for a security feature rather than a recovery tool.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

screen lock policy

A screen lock policy (e.g., Group Policy setting for interactive logon: Machine inactivity limit) automatically locks the workstation after a defined period of inactivity, requiring re-authentication. This directly prevents unauthorized physical access to unattended desktops in a warehouse environment, aligning with the principle of least privilege and physical security controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Event Viewer

    Why it's wrong here

    Event Viewer is a passive monitoring console that records application, security, and system events, but it cannot enforce controls or block unauthorized interaction with an active desktop session. In a warehouse setting, inspecting logs after an incident is useful for forensic analysis, yet the immediate protective goal requires a proactive mechanism that locks the workstation before a passerby can access it.

  • ✓

    screen lock policy

    Why this is correct

    A screen lock policy, enforced through Windows security settings or Group Policy, automatically locks the interactive session after a defined idle timeout (for example, 'Interactive logon: Machine inactivity limit' or a password-protected screensaver). This forces the legitimate user to reauthenticate before continuing, which directly prevents physical unauthorized access to an unattended warehouse desktop. Because the immediate goal is to protect the active session and data, this policy is the correct first-line control.

  • ✗

    System Restore

    Why it's wrong here

    System Restore maintains restore points that capture critical system files, registry settings, and installed drivers, enabling rollback after problematic updates or corruption. However, it does not mitigate the immediate physical threat to an unattended warehouse desktop because it neither locks the active session nor protects data in memory or open files. Its value lies in extended recovery and maintenance, not real-time protection.

  • ✗

    Local Users and Groups

    Why it's wrong here

    Local Users and Groups manages user accounts, group memberships, and workstation permissions, but it does not control the behavior of a session that is already in progress. While restricting who can log on reduces the attack surface, this snap-in cannot establish an idle-timeout policy or force a lock when an authorized user steps away. The immediate protective action depends on a session lock mechanism, not on account administration.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.