220-1202 Security Practice Question
A technician is configuring a Windows 11 workstation for a small business that handles credit card payments. The owner wants to ensure that stored cardholder data cannot be read if the drive is removed and attached to another computer. Which Windows feature should the technician enable?
⚠ Common exam trap
Many candidates confuse file-level encryption such as EFS with full-disk encryption such as BitLocker, which leads to choosing a partial solution that leaves most data exposed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BitLocker
BitLocker encrypts the entire volume, so if the drive is removed and connected to another computer, the data remains unreadable without the recovery key or the original TPM. EFS, firewall rules, and UAC do not provide full-volume encryption, so they fail the physical-theft requirement. BitLocker is the correct built-in Windows feature for protecting data at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
BitLocker
Why this is correct
BitLocker provides full volume encryption for Windows 11, protecting data at rest so a removed drive cannot be read on another system. Enabling it on the OS drive with a TPM satisfies the requirement to render cardholder data unreadable if the disk is physically stolen. It is the built-in Windows feature that directly addresses this scenario.
- ✗
Encrypting File System (EFS)
Why it's wrong here
EFS encrypts individual files and folders for the user account that encrypted them. It does not protect the entire volume, and if the drive is removed, files not explicitly encrypted remain readable. It also depends on user certificates, which complicates recovery. EFS does not meet the requirement to protect all stored cardholder data at rest.
- ✗
Windows Defender Firewall
Why it's wrong here
Windows Defender Firewall filters network traffic to block unauthorized inbound and outbound connections. It has no capability to encrypt data stored on a disk, so removing the drive and attaching it elsewhere would still expose the cardholder data. This is a network control, not a data-at-rest protection mechanism.
- ✗
User Account Control (UAC)
Why it's wrong here
UAC prompts for elevation when administrative actions are attempted, helping prevent unauthorized system changes. It does not encrypt files or volumes, so physical removal of the drive would still allow an attacker to read the data. UAC addresses privilege escalation, not confidentiality of stored data.
Go deeper
Related to this question
Learn chapter
Data Security and Privacy Best Practices
Key term
BitLocker Encryption
BitLocker Encryption is a full-disk encryption tool built into Windows that protects data by encrypting the entire drive so that it cannot be read without the correct password or recovery key.
Key term
Firewall Configuration
Firewall configuration is the process of setting rules that control which network traffic is allowed to enter or leave a computer or network, acting as a security gatekeeper.
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.