mediumMultiple ChoiceObjective-mapped
220-1202 Deploying new laptops to remote workers Practice Question
A company is deploying new laptops to remote workers. They need to ensure that if a laptop is stolen, the data on it cannot be accessed. Which two physical security controls should be configured before shipment?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Full-disk encryption and a BIOS/UEFI password.
Full-disk encryption protects data at rest, and a BIOS/UEFI password prevents unauthorized booting or tampering with boot settings. This question tests the combination of controls needed for remote device security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cable lock and privacy filter.
Why it's wrong here
A cable lock (e.g., Kensington lock) is a physical deterrent against the theft of the entire device, requiring a fixed anchor point, which is often unavailable or impractical for remote workers. A privacy filter only prevents shoulder surfing by limiting the screen's viewing angle, offering no protection for the data stored on the laptop's drive if the device is stolen or accessed by unauthorized individuals. Neither of these measures directly addresses the security of the data itself against unauthorized access.
- ✓
Full-disk encryption and a BIOS/UEFI password.
Why this is correct
Full-disk encryption (FDE) renders all data on the laptop's storage unreadable without the correct decryption key, effectively protecting sensitive information even if the physical device is lost or stolen and the drive is removed. A BIOS/UEFI password prevents unauthorized users from booting the system from external media, disabling security features, or altering critical boot settings, thereby reinforcing the FDE by preventing bypass attempts. This combination directly addresses both data confidentiality and system integrity for remote workers.
- ✗
Smart card reader and biometric scanner.
Why it's wrong here
Smart card readers and biometric scanners (like fingerprint readers) are strong authentication methods primarily used to control access to the operating system or specific applications. While they enhance user authentication, they do not inherently encrypt the data on the storage drive. If the laptop's drive is physically removed and connected to another computer, the data would remain unencrypted and fully accessible, completely bypassing these OS-level access controls.
- ✗
Asset tracking tag and a Kensington lock slot.
Why it's wrong here
An asset tracking tag, typically a barcode or RFID tag, aids in inventory management and physical recovery of a lost or stolen device by identifying it within a company's assets. A Kensington lock slot is a physical port designed to accept a cable lock, providing a deterrent against opportunistic theft of the entire laptop. Neither of these measures provides any cryptographic protection for the sensitive data stored on the laptop's hard drive, leaving the information vulnerable if the device is compromised.
Go deeper
Related to this question
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.