hardMultiple ChoiceObjective-mapped
220-1202 Practice Question: A company's security policy requires that all…
A company's security policy requires that all laptops have a TPM chip enabled and be configured to require a PIN at startup before the operating system loads. Which security feature is being configured?
⚠ Common exam trap
It's easy for candidates to confuse Secure Boot (which only verifies bootloader integrity) with the full-disk encryption and pre-boot authentication provided by BitLocker with TPM+PIN.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BitLocker with TPM and PIN protector
The scenario describes using a TPM chip and requiring a PIN at startup before the OS loads. This is exactly how BitLocker's TPM+PIN protector works: the TPM validates the system integrity, and the PIN provides an additional factor of authentication, unlocking the drive encryption key before Windows boots. Option B is correct because it directly matches the described configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Secure Boot
Why it's wrong here
Secure Boot is a Unified Extensible Firmware Interface (UEFI) feature designed to enhance system security by ensuring that only digitally signed and trusted software, such as boot loaders and operating system components, can load during the startup process. It verifies cryptographic signatures against a database of trusted keys to prevent malware from hijacking the boot chain. However, Secure Boot primarily focuses on boot integrity and does not provide full-disk encryption or require a user-entered Personal Identification Number (PIN) for pre-boot authentication to unlock data.
- ✓
BitLocker with TPM and PIN protector
Why this is correct
BitLocker with a Trusted Platform Module (TPM) and PIN protector is a robust full-disk encryption solution that directly addresses the security requirement for laptops. The TPM provides a hardware-based root of trust, verifying the system's integrity before releasing the encryption key to unlock the drive. Adding a PIN protector requires the user to enter a specific code before the operating system even begins to load, providing a crucial second factor of authentication (something you know) in addition to the TPM's hardware validation (something you have), thereby securing data even if the laptop is stolen or the TPM is tampered with.
- ✗
Windows Defender System Guard
Why it's wrong here
Windows Defender System Guard is a suite of security features within Windows that aims to protect the operating system's integrity from advanced attacks, particularly those that attempt to compromise the system during startup. It leverages hardware virtualization and Hypervisor-protected Code Integrity (HVCI) to isolate critical system components and prevent malicious code execution. While System Guard is vital for maintaining OS integrity, its function does not include full-disk encryption or requiring a user PIN for pre-boot authentication to access the encrypted drive.
- ✗
Group Policy password complexity enforcement
Why it's wrong here
Group Policy password complexity enforcement defines rules for user account passwords within an organization, such as minimum length, required character types (e.g., uppercase, numbers, symbols), and password history. These policies are applied at the operating system login stage, *after* the system has booted and the user attempts to authenticate to their account. They do not provide pre-boot authentication for the entire drive, nor do they require a PIN to unlock the laptop's storage before the operating system even begins to load.
Go deeper
Related to this question
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.