A technician finishes a password reset at a user's desk, walks away to grab a cable, and comes back to find a coworker reading the still-open ticket queue over the unattended keyboard. Nothing was hacked. No malware ran. The only thing that failed was a habit: nobody pressed Win+L before stepping away. Many security incidents a help desk deals with start exactly this way, with an ordinary person skipping an ordinary precaution.
CompTIA A+ Core 2 (220-1202) covers this ground in the Security domain, under the objective on workstation security best practices. The exam expects you to know the behaviors that keep a workstation and its data safe: locking and logging off, securing the physical device, protecting personally identifiable information (PII), practicing good password hygiene, and using a password manager. Related articles go deeper on specific pieces: "Password Considerations" for password policy, "Account Management" for lockout and account policies, and "Hardening Tips" for locking down the system itself. This article stays focused on what the user at the keyboard should do.
Locking the screen is the fastest security habit you can build
A locked screen keeps the session running but demands authentication before anyone can see or touch anything. It should be as automatic as pushing in your chair.
On Windows, press Win + L to lock instantly. On macOS, press Control + Command + Q. Both shortcuts leave every application open exactly where you left it; you unlock and keep working. That zero-cost resume is why "it's only for a minute" is never an excuse to skip it. A minute is plenty of time for someone to read an open email, photograph a customer record, or send a message from your account.
Exam tip: when a scenario says a user is "stepping away briefly," the best practice CompTIA wants is locking the screen, not shutting down, not logging off, and never leaving the session open.
Automatic lock timeouts catch the moments you forget
Habits fail, so a well-configured workstation locks itself after a period of inactivity and requires the user's password (or PIN, fingerprint, or other configured sign-in method) to resume. The shortcut covers the times you remember; the timeout covers the times you don't.
On Windows, the pieces live in Settings: screen timeout behavior sits under the power and screen settings, and the requirement to sign in again after the machine wakes sits under the sign-in options in the Accounts area. The legacy screen saver dialog, still reachable from the lock screen personalization settings, has the checkbox that shows the logon screen on resume. In a business environment, administrators enforce an inactivity lock on every machine through Group Policy, the Windows mechanism for pushing settings to domain-joined computers; if you can't change the timeout at all, that's the policy doing its job.
On macOS, open System Settings and look at the Lock Screen section, which controls how quickly the display sleeps or the screen saver starts when the Mac is inactive, and how soon after that a password is required. Requiring the password immediately, rather than after a grace period, is the secure choice.
Keep the timeout short wherever other people can reach the machine. A public-facing counter workstation might lock after a minute or two; a private office can tolerate more. On shared or public-facing machines, exposure outweighs convenience every time.
Locking, logging off, and switching users are different actions with different effects
These three options sit next to each other in the operating system, and the exam tests whether you know what each one does.
Locking hides the session behind the login prompt but leaves it fully running: applications stay open, files stay loaded, network connections stay live. It's the right choice when the same person is coming back to the same machine.
Logging off (signing out) ends the session. Applications close, unsaved work is at risk, and the next person starts a fresh session under their own account with their own permissions. It's slower to resume from, but it fully separates one user's activity from the next.
Switching users leaves the first session running in the background while a second person signs in to their own. It's convenient on a home PC, but every backgrounded session still consumes memory and holds open files and connections until its owner returns to close it down.
On shared machines, log-off discipline matters. A lab computer or front-desk PC serves many users a day, and a session left locked-but-running blocks the next user and leaves the first user's files and credentials resident on an abandoned machine. The rule on shared hardware: locking is for short absences by the same user; logging off is for handing the machine over or leaving for the day.
Physical security keeps the device itself out of the wrong hands
Every software control on a laptop assumes the attacker doesn't simply pick the laptop up and leave. End-user physical security closes that gap with unglamorous but effective habits.
A cable lock is a hardened cable that loops around a fixed object and anchors into the security slot built into many laptops and monitors. It won't stop a determined thief with bolt cutters and time, but it defeats the grab-and-go theft that actually happens in libraries, conference rooms, coffee shops, and open-plan offices. Anyone working in public spaces or an unsecured office should carry one.
Never leave a device in a vehicle. A laptop bag on a car seat is an advertisement, a broken window takes seconds, and the trunk is only a slightly better gamble. The rule that survives every scenario: the device travels with the person.
A privacy screen (privacy filter) is a film over the display that narrows the viewing angle so the screen is readable only from straight on.