hardMultiple ChoiceObjective-mapped
220-1201 Practice Question: A technician is configuring an MFP for a law firm…
A technician is configuring an MFP for a law firm that requires secure printing. Users must enter a PIN at the device to release their print jobs. The MFP supports hard drive encryption and secure print release. Which feature should the technician enable to ensure print jobs are not stored unencrypted on the MFP's hard drive?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hard drive encryption
Secure print release only holds jobs until the user enters a PIN, but the data may still be stored on the hard drive. Hard drive encryption ensures that even if the drive is removed, the data is unreadable. Both features together provide comprehensive security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Secure Print (PIN release)
Why it's wrong here
Secure Print (PIN release) is an access control feature designed to prevent unauthorized individuals from physically collecting printed documents from the MFP's output tray. While it holds print jobs in a queue until a user authenticates with a PIN at the device, this mechanism primarily controls access to the *output* and does not encrypt the print job data itself while it is stored on the MFP's internal hard drive awaiting release. Therefore, it does not protect data at rest from physical access to the storage medium.
- ✗
IPsec for network printing
Why it's wrong here
IPsec (Internet Protocol Security) for network printing encrypts data as it traverses the network from the user's computer to the MFP. This protects the confidentiality and integrity of print jobs *in transit*, safeguarding against eavesdropping or tampering during network transmission. However, once the print job data arrives at the MFP and is spooled to its internal hard drive for processing, IPsec's encryption is no longer applied, leaving the data vulnerable if the drive is physically removed or accessed directly.
- ✓
Hard drive encryption
Why this is correct
Hard drive encryption, often implemented as Full Disk Encryption (FDE) or using self-encrypting drives (SEDs), scrambles all data written to the MFP's internal storage media. This ensures that any print jobs, cached documents, or configuration files stored on the device's hard drive are unreadable without the correct decryption key. Consequently, if the hard drive is physically removed from the MFP or the device is stolen, the sensitive data at rest remains protected and inaccessible to unauthorized parties.
- ✗
User authentication via LDAP
Why it's wrong here
User authentication via LDAP (Lightweight Directory Access Protocol) integrates the MFP with a centralized directory service, requiring users to log in with network credentials before accessing printing, scanning, or copying functions. This provides robust access control, ensuring that only authorized users can operate the device and submit jobs. However, LDAP authentication does not encrypt the actual print job data once it is spooled and stored on the MFP's internal hard drive, meaning it does not protect data at rest from direct physical access to the storage.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 220-1201 question from scratch — 972 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1201 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1201 exam.