Objective 2.2220-1202

2.2 Given a scenario, configure and apply basic Microsoft Windows OS security settings.

Objective 2.2 sits in Security, which carries 28% of the A+ Core 2 exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

SecurityEasy

A user signs in as a local administrator on a Windows 11 PC with UAC enabled. Which access token does Windows use to launch explorer.exe and display the desktop?

Correct.

The concept

UAC creates two access tokens for administrator accounts at sign-in and uses the lower-privilege one by default.

Why this answer

Explorer.exe, the parent process for user-initiated tasks, always runs under the standard user access token so that apps inherit standard privileges unless elevation is approved.

  • Correct: this is the token used by default for the desktop and standard apps.
  • BThis token is only invoked after the user approves an elevation prompt for an administrative task.
  • CNot a token type UAC creates for interactive sign-in.
  • DThis relates to Kerberos authentication, not the UAC token model.
Read the sourceMicrosoft Learn: How User Account Control works
Verified against learn.microsoft.com · 2026-07-27
uacaccess-tokenlogin-os-optionsusers-and-groups

Now you: objective 2.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 2

SecurityModerate

A standard user account tries to install a printer driver that requires administrative rights. UAC prompts the user to type a local administrator's username and password before continuing. Which UAC element is this?

Sample question 2 of 2

SecurityModerate

A security administrator wants to isolate NTLM password hashes and Kerberos ticket-granting tickets so malware running with administrative privileges cannot extract them for pass-the-hash attacks. Which Windows feature accomplishes this?

Full A+ Core 2 question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Security