How to Manage and Configure Basic Security Settings in Windows for CompTIA A+ Core 2 (220-1102)
Introduction: what CompTIA means by basic Windows security settings
For A+ Core 2, this objective is really about support decisions: which built-in Windows tool fits the symptom, what is the least-privilege fix, and how do you verify it worked without weakening the system. In day-to-day support, “basic Windows security settings” usually means local accounts and groups, UAC, Microsoft Defender Antivirus, Microsoft Defender Firewall, NTFS and share permissions, BitLocker or Device Encryption, sign-in options, Windows Update, and recovery tools like Safe Mode and WinRE.
The best workflow is simple: verify the current state, make the smallest secure change, test the exact task, document it, and escalate if policy or management tools are involved. That mindset matters because CompTIA loves tempting shortcut answers like “make the user an administrator” or “turn the firewall off.” Those are usually the wrong fixes.
Exam trap to remember: UAC is not the same as permissions.
Microsoft Defender Antivirus isn’t the same as Microsoft Defender Firewall, either.
NTFS permissions aren’t share permissions, and that distinction trips people up constantly. It’s one of those sneaky exam traps that looks obvious right up until you’ve got a user telling you they can open a file from the office PC but suddenly can’t get to the same file over the network share.
That’s the point where the details really matter.
A password is not the same thing as encryption.
Security basics that drive the right answer
The principle of least privilege means users and apps should have only the access they need.
From a support standpoint, a standard user for daily work is a lot safer than leaving somebody as a permanent local admin.
If somebody needs access to one folder, give them access to that folder.
Don’t hand them the keys to the whole machine just because one app or one folder is being difficult.
If an app needs elevation once, elevate that task and move on. That’s the cleaner fix nine times out of ten.
Do not widen access just because it is faster.
Also keep authentication and authorization separate.
Authentication is how you prove who you are — password, PIN, fingerprint, face sign-in, that kind of thing.
Authorization is what you’re allowed to do after you’ve signed in — things like opening a folder, installing software, changing system settings, or using Remote Desktop.
If the user can sign in but cannot save to a folder, that is usually authorization, not authentication.
Windows security is layered: account type, UAC, antivirus, firewall, permissions, encryption, updates, and recovery. One failed layer does not make the others irrelevant.
Know the Windows tools and edition limits
Windows has multiple admin tools, and A+ expects recognition-level familiarity. The important part is knowing what each one is for and when it may be missing.
Common tools and what they do
Windows Security: status for Microsoft Defender Antivirus, Microsoft Defender Firewall, Device security, App & browser control, and protection history.
Computer Management / compmgmt.msc: access to snap-ins like Local Users and Groups on supported editions, Shared Folders, Event Viewer, and Device Manager. It is not full endpoint management; it is a local admin console.
lusrmgr.msc: Local Users and Groups on Pro, Enterprise, and Education editions. It is generally unavailable on Home edition.
secpol.msc: Local Security Policy on Pro, Enterprise, and Education editions.
It’s useful for local password policy, lockout policy, and security options on standalone systems.
On domain-joined PCs, effective password policy is usually controlled by domain policy, not local policy.
gpedit.msc: Local Group Policy Editor on Pro, Enterprise, and Education editions. It is generally unavailable on Home edition.
services.msc: service status and startup behavior.
wf.msc: Windows Defender Firewall with Advanced Security.
control: Control Panel, including User Accounts and BitLocker Drive Encryption on supported editions.
Useful commands: net user, whoami /groups, manage-bde -status, PowerShell Get-LocalUser, and Get-MpComputerStatus.
Accounts, groups, and UAC
Windows 10 and 11 may use a local account, a Microsoft account, or a work or school account such as Microsoft Entra ID. That matters for password resets. A local account password is reset locally. A Microsoft account often follows Microsoft account recovery. Work-managed accounts may require organizational tools or escalation.
Local account tasks
On Pro and higher, open lusrmgr.msc or Computer Management > Local Users and Groups.
To create a user: right-click Users > New User.
To disable an account: open its properties and check Account is disabled. To reset a local password: right-click the account and choose Set Password. To add a user to a group: open Groups, double-click Administrators or Remote Desktop Users, then add the account.
Command-line examples are exam-useful too: net user trainee P@ssw0rd! /add creates a local user, and net localgroup "Remote Desktop Users" trainee /add adds that user to the RDP group.
UAC
UAC is about elevation, not resource permissions. The normal graphical path is Control Panel > User Accounts > Change User Account Control settings, or you can search for UAC.
For standard users, elevation usually means a credential prompt for admin credentials.
For administrators running in Admin Approval Mode, it’s usually a consent prompt.
Prompts typically appear on the secure desktop, dimming the screen to reduce spoofing risk.
The slider changes notification behavior.
Turning UAC down too far, or disabling it entirely, weakens security and can also create weird app compatibility issues, especially around file or registry virtualization.
A common support action is right-clicking an installer and choosing Run as administrator instead of changing the whole account type.
CompTIA trap: a UAC prompt does not mean the user automatically has access to a folder or share. That is still a permissions issue.
Local policy basics: passwords and lockouts
On supported editions, secpol.msc lets you review local password policy and account lockout policy on standalone systems.
Useful settings include minimum password length, password complexity, password history, maximum password age, account lockout threshold, lockout duration, and the reset counter.
If a domain-joined computer keeps following stricter rules than the local settings you changed, domain policy is the likely reason.
A practical example: repeated failed sign-ins trigger account lockout.
And no, the fix is not to turn security off.
Verify whether the account is locked, wait for the lockout duration or unlock through the appropriate admin process, then find the cause of the bad-password attempts.
Microsoft Defender Antivirus: what to check first
Use the current name: Microsoft Defender Antivirus. Open Windows Security > Virus & threat protection. Check real-time protection, protection updates, scan options, and Protection history.
Scan types
Quick scan: first pass for common malware locations.
Full scan: broader inspection of the system.
Custom scan: specific folder, drive, or USB device.
Microsoft Defender Offline scan: useful when persistent malware or rootkit-style behavior is suspected.
Quarantine and exclusions
Protection history shows detections and actions.
If a legitimate file got quarantined, don’t just restore it blindly — review it carefully first.
I’ve seen people undo the protection before they even know what got flagged.
Exclusions should be narrow, documented, and justified.
“The app is slow” is not a good reason for a broad exclusion.
Troubleshooting note
If Microsoft Defender Antivirus appears off, first check Windows Security status and whether a third-party antivirus product is registered.
On modern Windows, Microsoft Defender Antivirus may go into a passive or disabled state when a supported third-party antivirus product is active.
Don’t start by changing services unless you know the device is unmanaged and that’s actually the cause.
If you do need service awareness, relevant names include WinDefend and wscsvc.
For command-line verification, PowerShell Get-MpComputerStatus is useful.
Microsoft Defender Firewall: profiles, rules, and safe fixes
Microsoft Defender Firewall is a host-based stateful firewall. It filters inbound and outbound traffic, but on Windows clients the default posture is usually most noticeable on inbound traffic: inbound is generally blocked unless allowed, while outbound is generally allowed unless blocked by rule or policy.
Open the simple view in Windows Security > Firewall & network protection, or use wf.msc for advanced rules.
Profiles
Public: most restrictive default posture for untrusted networks.
Private: trusted-network behavior for things like discovery and sharing when appropriate.
Domain: applied when the machine can authenticate to a domain controller, not just because it is on a company network.
Rule basics
Program rules allow a specific app path.
Port rules allow traffic on a specific TCP or UDP port.
Scope can limit remote IPs. Profiles can limit where the rule applies. That is why “allow the app on Private only” is much better than “disable the firewall.”
Mini lab: open wf.msc > Inbound Rules > New Rule. Choose Program for an app-based exception or Port for a service port. Choose Allow the connection, then limit it to the correct profile, such as Private only. Verify by testing the app on the intended network and confirming it still fails on profiles you did not open.
Permissions: NTFS, share access, inheritance, and ownership
NTFS permissions control local file system access on NTFS volumes.
Common permissions you’ll see are Read, Write, Modify, and Full Control.
The important correction here is that Modify includes read and execute, write, and delete. Full Control includes Modify plus changing permissions and taking ownership.
NTFS vs share permissions
Share permissions apply only to SMB share access over the network. They do not control local console access.
For local access, NTFS permissions are what matter.
For network share access, effective access is the intersection of share permissions and NTFS permissions.
Inheritance and move or copy rules
Copying to a new location usually inherits destination folder permissions.
Moving within the same NTFS volume usually keeps the existing permissions.
Moving to a different volume behaves like copy then delete, so destination inheritance usually applies. This is one of those details that explains a lot of “it worked yesterday” tickets.
In Advanced Security Settings, you can review inherited versus explicit permissions, ownership, and Effective Access. Deny entries should be used carefully because they can override allowed access in ways that are hard to troubleshoot.
Mini lab: create a folder, open Properties > Security > Edit, add one user, and grant Modify instead of Full Control. Verify the user can create, edit, and delete files in that folder but cannot change permissions.
BitLocker, Device Encryption, and recovery
BitLocker is full-drive encryption, mainly available on Pro, Enterprise, and Education editions. Device Encryption may appear on some Home systems if hardware and sign-in requirements are met. BitLocker commonly uses a TPM, but TPM is not the only possible configuration.
A password protects sign-in.
BitLocker protects data at rest, which means it helps if somebody pulls the drive out of a laptop and tries to read it somewhere else.
That is the exam distinction.
Use Control Panel > BitLocker Drive Encryption or manage-bde -status to verify protection.
Before you turn it on, confirm where the recovery key is being backed up.
Common destinations include a Microsoft account, Microsoft Entra ID, Active Directory, or a saved file or printout depending on policy.
Important support behavior: suspend BitLocker before some BIOS or firmware changes, then resume it afterward.
Recovery prompts can absolutely show up after hardware or firmware changes.
If the user gets a BitLocker recovery screen, the fix is the recovery key, not random reboot attempts.
Sign-in options, Hello, and update hygiene
Windows Hello adds PIN, fingerprint, or face sign-in on supported hardware.
The PIN is device-bound and cryptographically tied to that device — it’s not just a shorter password with fewer characters.
If Hello options are unavailable, check hardware support, driver status, and whether policy blocks setup.
For updates, open Settings > Windows Update.
It helps a lot to know the difference between quality updates, feature updates, driver updates, and optional updates.
If updates fail, I’d check for a pending restart, low disk space, network access, update history, and the Windows Update troubleshooter.
If a bad update broke startup, WinRE lets you uninstall recent updates.
Remote access and sharing: secure basics
Remote Desktop hosting is supported on Pro, Enterprise, and Education editions, not Home.
Home can still act as an RDP client, though.
For inbound RDP, verify the edition, enable Remote Desktop, confirm the user is authorized, check firewall rules, and make sure the network path is actually reachable.
Membership in Remote Desktop Users is often part of the answer, but managed environments may also require policy allowances.
Use Network Level Authentication when available, and do not expose RDP directly to the internet. Safer practice is a VPN, an RD Gateway, or another controlled remote-access method with multifactor authentication where possible.
For file sharing, remember the stack: correct network profile, share permissions, and NTFS permissions. If a user can access a folder locally but not across the network, check the share layer.
Safe Mode vs WinRE
Use Safe Mode when Windows still boots but is unstable, a startup app is interfering, or you need a minimal environment. Safe Mode with Networking is useful if you need network access for updates or tools. Safe Mode is helpful, but it is not guaranteed malware cleanup.
Use WinRE when Windows will not boot normally or you need deeper repair tools.
WinRE gives you tools like Startup Repair, System Restore, Command Prompt, Uninstall Updates, and Startup Settings.
Common entry methods include Shift + Restart from the sign-in screen or Settings, or repeated failed boots.
Troubleshooting matrix for exam scenarios
User can sign in but cannot save to a shared folder: likely an authorization issue.
Check NTFS permissions and share permissions.
The secure fix is to grant the minimum access needed.
Verify with the user account.
App works on office LAN but not home Wi-Fi: likely a network profile or firewall scope issue.
Check the active profile and the rule scope.
Secure fix: allow the app on the correct profile, not all profiles.
Microsoft Defender Antivirus says protection is off after installing third-party antivirus: check Windows Security status and antivirus registration. Secure fix: verify approved protection is active; do not assume both products should scan simultaneously.
Laptop prompts for BitLocker recovery after a firmware update: this is an expected possibility if protection was not suspended. Secure fix: use the recovery key, then review the pre-maintenance process.
RDP works internally but not remotely: often a VPN or exposure design issue.
Check the edition, user rights, firewall, and whether the remote user is actually on the VPN.
Do not open RDP broadly to the internet as a shortcut.
Repeated bad sign-in attempts caused lockout: check local or domain lockout policy. Secure fix: clear the lockout through the proper process and find the bad password source.
How I would study this for A+ Core 2
Practice by tool and by symptom.
Open Windows Security, review Protection history, run a Quick scan, and find the Offline scan option.
Open wf.msc and identify the active profile. Create one test folder and assign Modify without Full Control. Check BitLocker status in the graphical interface and with manage-bde -status. Create a local test user on a Pro lab virtual machine and add that user to Remote Desktop Users instead of Administrators. Open secpol.msc on a supported edition and find password policy and lockout policy.
Top exam traps: logon problem versus access problem, UAC versus permissions, firewall versus antivirus, password versus encryption, share permissions versus NTFS, and “make them admin” versus the least-privilege fix.
Conclusion
The heart of this objective is choosing the right built-in Windows control without overcorrecting. Think in layers, use the least-privilege fix, and verify the exact result. If you can look at a symptom and quickly map it to the right tool, the right secure change, and the right verification step, you are thinking like both a solid support technician and a strong A+ candidate.