Courseiva
Operating Systems →mediumMultiple Choice

220-1102 Operating Systems Practice Question

A technician needs to test a downloaded executable file from an untrusted source on a Windows 10 Pro workstation. The technician wants to run the file in an isolated environment without affecting the host operating system and without using a separate virtual machine. Which built-in Windows feature should the technician use?

⚠ Common exam trap

It's easy for candidates to confuse Hyper-V Manager with Windows Sandbox, assuming any virtualization tool requires a full VM setup, but Windows Sandbox is specifically designed for lightweight, disposable isolation without manual VM creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Windows Sandbox

Windows Sandbox is a built-in Windows 10 Pro and Enterprise feature that creates a lightweight, isolated desktop environment to run untrusted applications. It uses hardware-based virtualization to ensure the host OS remains unaffected, and the sandbox is discarded after closure, meeting the requirement of no separate VM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hyper-V Manager

    Why it's wrong here

    Hyper-V Manager creates full virtual machines with separate guest operating systems, which violates the stem’s explicit constraint of not using a separate virtual machine. It is tempting because Hyper-V is a built-in isolation tool for running untrusted software, and in scenarios where a full VM is permitted, it would be the correct choice for sandboxing an executable.

  • ✓

    Windows Sandbox

    Why this is correct

    Windows Sandbox is a lightweight, ephemeral virtualized environment that uses the host's kernel to start a clean, disposable Windows desktop in seconds. It provides true isolation for running downloaded executables—any changes, malware, or system effects inside the sandbox vanish when it is closed, leaving the host completely untouched. This directly matches the scenario's need to test an untrusted file without deploying a full separate virtual machine, making it the correct choice.

  • ✗

    System Restore

    Why it's wrong here

    System Restore creates snapshots of critical system files and registry keys that can be rolled back later, but it does nothing to isolate a running process. When you execute the downloaded file, it still has full access to your user profile, network, and installed programs, and can cause damage or exfiltrate data before you even think about reverting. Additionally, many malware samples aggressively clear or disable restore points, leaving you without a fallback. System Restore is a post-incident recovery tool, not a sandbox.

  • ✗

    Windows Defender Application Guard

    Why it's wrong here

    Windows Defender Application Guard (WDAG) is a hardware-isolated container built into Windows and Microsoft Defender for Endpoint, but it is exclusively designed to protect browser sessions—specifically Microsoft Edge and Office—from malicious web content. It does not provide a mechanism to load and execute a random downloaded .exe in an isolated desktop; launching an untrusted executable still falls outside its scope. While it does use Hyper-V and hardware virtualization, its threat model is about containing web-based attacks, not arbitrary file execution, so it is not a valid answer here.

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.