easyMultiple ChoiceObjective-mapped
SSCP Practice Question: A university IT department manages a lab of 50…
A university IT department manages a lab of 50 computers running Windows 10 that are used by students for coursework. The computers are joined to a domain and have Group Policy applied to restrict administrative access. Recently, several students were able to install unauthorized software by using the built-in Administrator account, which had the same password on all lab computers. The IT department wants to prevent this without affecting the students' ability to run required academic software. Which of the following is the most effective solution?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a tool to assign a unique, random password to the local Administrator account on each computer.
Assigning a unique, random password to the local Administrator account on each computer prevents unauthorized use of that account without impacting normal user operations. Option A is incorrect because configuring computers to only allow standard user accounts would prevent students from installing unauthorized software, but it might also block required academic software that needs administrative privileges, and it does not address the vulnerability of the shared Administrator account. Option B is incorrect because disabling the local Administrator account could break legitimate administrative tasks or require alternative methods, and it does not prevent students from using other accounts with admin privileges. Option D is incorrect because Software Restriction Policies can block unauthorized executables, but they do not prevent students from directly using the Administrator account to bypass restrictions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the computers to only allow standard user accounts.
Why it's wrong here
This does not prevent students from using the local Administrator account if they know the password, as they could still log in with that account.
- ✗
Disable the local Administrator account on all lab computers.
Why it's wrong here
Disabling the local Administrator account might break functionality if it is relied upon by some software or processes, and it may not be feasible if the account is needed for administrative tasks.
- ✓
Use a tool to assign a unique, random password to the local Administrator account on each computer.
Why this is correct
Assigning a unique, random password to the local Administrator account on each computer prevents students from using a common password to gain administrative access, thereby stopping unauthorized software installations.
- ✗
Implement Software Restriction Policies to block unauthorized executables.
Why it's wrong here
Software Restriction Policies can block specific executables, but they do not prevent students from using the Administrator account to bypass restrictions, as the account itself is not restricted.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 920-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.