220-1102 Software Troubleshooting Practice Question
A user reports that when they try to launch a specific application on Windows 10, they receive the error 'This application has been blocked by your system administrator'. The technician verifies that the user has local administrator rights and the application is installed in the default location. Which configuration should the technician check to resolve this issue?
⚠ Common exam trap
Many candidates assume local administrator rights bypass all restrictions, but AppLocker and Software Restriction Policies can still block execution regardless of user privileges, leading them to incorrectly choose UAC settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AppLocker or Software Restriction Policies
The error 'This application has been blocked by your system administrator' is typically generated by AppLocker or Software Restriction Policies (SRP), which are Windows security features that control which executables can run. Even though the user has local administrator rights, these policies can still block applications based on rules such as publisher, path, or hash. The technician should check the local or domain Group Policy settings for AppLocker or SRP to identify and modify the blocking rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
User Account Control (UAC) settings
Why it's wrong here
UAC is a consent and credential prompt that appears only when an application requests administrative privileges or attempts an elevated action. It never denies an application from launching under the user's standard token; instead, it either shows an elevation prompt or runs the process with limited rights. A message stating that the program is blocked by an administrator is not UAC behavior, because UAC does not perform application allow/deny decisions based on executable identity.
- ✗
Windows Defender Firewall rules
Why it's wrong here
Windows Defender Firewall inspects network traffic using inbound and outbound rules tied to ports, programs, and IP addresses, and it applies based on the active network profile (Domain, Private, Public). It has no mechanism to block the local invocation of an executable file or to intercept the creation of a process by the shell or other applications. Therefore, a launch-time error indicating an administrator policy block cannot originate from firewall rules, which only govern communication between the host and network peers.
- ✓
AppLocker or Software Restriction Policies
Why this is correct
AppLocker and Software Restriction Policies are Windows application-control features that administrators use to restrict which files can be run on a system. AppLocker builds rules from file path, publisher, or hash, and can enforce allow-list or deny-list behavior across executable, script, MSI, and DLL rule collections; Software Restriction Policies are the older, coarser mechanism using similar path, hash, certificate, and registry rules. When a matching rule blocks an application, Windows often displays a message saying the program has been blocked by an administrator or by software restriction policy, which exactly matches the scenario described in the question.
- ✗
Group Policy update interval
Why it's wrong here
The Group Policy update interval determines how often domain-based policies are refreshed in the background—by default every 90 minutes with a random offset, and always at system startup. If the policy that blocks the application is already applied to the session, the refresh interval is irrelevant to the current login session; the block is active immediately. The interval affects when newly assigned or changed policies take effect, not whether an existing policy is currently enforcing its restriction. Thus, waiting or adjusting the interval would not explain or fix the immediate launch denial.
Visual reference
Go deeper
Related to this question
Learn chapter
Workgroup vs Domain Join
Key term
AppLocker
AppLocker is a Windows security feature that helps IT administrators control which applications and files users are allowed to run on their computers.
Key term
Group Policy
Group Policy is a Windows-based feature that allows administrators to centrally manage and enforce settings for users and computers across an organization.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.