220-1102 Security Practice Question
The IT director wants to ensure that all HR workstations are consistently configured with the same security settings, such as password policies and firewall rules. The workstations are all running Windows 10 Pro and are part of an Active Directory domain. Which method should the technician use to enforce these settings automatically?
⚠ Common exam trap
Many exam-takers confuse auditing (Option A) with enforcement, or assume a written policy (Option D) is sufficient for technical configuration, when only Group Policy can automatically and persistently apply security settings across domain-joined Windows machines.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Group Policy
Group Policy in Active Directory allows administrators to centrally define and enforce security settings like password policies and firewall rules across all domain-joined Windows 10 Pro workstations. By linking a Group Policy Object (GPO) to an Organizational Unit (OU) containing the HR computers, the settings are automatically applied at startup and periodically refreshed, ensuring consistent configuration without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy a security audit log configuration
Why it's wrong here
Security audit log configuration is a passive monitoring control; it records events such as sign-in attempts, privilege usage, and policy changes but never alters workstation settings. Even if HR workstations log every action, the logs do not enforce password complexity, firewall rules, or any baseline configuration. To actually apply and enforce security settings, you need an active management mechanism like Group Policy, not just a record of what happened.
- ✗
Implement data loss prevention (DLP) software
Why it's wrong here
Data loss prevention (DLP) software is purpose-built to inspect and block unauthorized transfers of sensitive data, typically through email, web, or removable media, rather than to manage endpoint security posture. It does not configure the OS-level settings needed on HR workstations, such as account lockout thresholds, audit policies, or Windows Firewall rules. For centralized enforcement of these types of security settings on domain-joined machines, Group Policy is the appropriate tool.
- ✓
Configure Group Policy
Why this is correct
Group Policy is the native Windows mechanism for centrally defining and enforcing security configurations on domain-joined computers; when you link a GPO to the HR Organizational Unit (OU), settings like password policies, audit policies, software restriction rules, and firewall rules are automatically applied and refreshed on each workstation. Because the HR machines are domain members, the GPO takes precedence over local security settings and helps ensure a consistent, managed security baseline. This active enforcement makes Group Policy the direct answer to the IT director's requirement.
- ✗
Distribute an Acceptable Use Policy (AUP)
Why it's wrong here
An Acceptable Use Policy (AUP) is a legal and procedural document that communicates expected behavior and sanctions for misuse, but it cannot automatically change workstation security settings or enforce technical controls. Distributing the policy only relies on employees' willingness to follow it and does nothing to guarantee that HR workstations have the required configurations. For binding policy into a machine, you need a technical tool like Group Policy, not an informational document.
Go deeper
Related to this question
Learn chapter
Password Managers and Best Practices
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
Key term
Group Policy
Group Policy is a Windows-based feature that allows administrators to centrally manage and enforce settings for users and computers across an organization.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.