Courseiva
hardMultiple ChoiceObjective-mapped

220-1102 Practice Question: A company laptop was stolen, and the IT…

A company laptop was stolen, and the IT department needs to ensure that the data on the device cannot be accessed. The laptop had BitLocker enabled, but the drive was unlocked when stolen. What additional security measure could have prevented data access in this scenario?

⚠ Common exam trap

CompTIA often tests the misconception that a strong user password or firewall is sufficient to protect data on a stolen device, but the key point is that BitLocker's pre-boot authentication (like a startup PIN) is the only measure that protects data when the drive is unlocked at the time of theft.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure BitLocker with a startup PIN

BitLocker with a startup PIN requires the user to enter a PIN before the OS loads, even if the drive was previously unlocked. Since the laptop was stolen while unlocked, the PIN would have prevented the drive from being decrypted after a reboot or power loss, protecting the data from unauthorized access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable Windows Defender Firewall

    Why it's wrong here

    Windows Defender Firewall primarily operates at the network layer, controlling inbound and outbound network traffic to protect against unauthorized network access or malware propagation. It offers no protection for data stored on a device that has been physically stolen, as an attacker with physical possession can bypass network defenses entirely to access the local storage. A firewall's function is to regulate network communications, not to encrypt or secure data on a physically compromised drive.

  • Configure BitLocker with a startup PIN

    Why this is correct

    Configuring BitLocker with a startup PIN provides robust full disk encryption, ensuring that all data on the drive is unreadable without the correct authentication. The startup PIN acts as a pre-boot authentication factor, requiring the user to enter it before the operating system can even begin to load and before the encryption keys are released by the Trusted Platform Module (TPM). This prevents unauthorized access to data even if the drive is removed and placed into another computer or if the device is booted from an external medium.

  • Use a strong user password

    Why it's wrong here

    A strong user password primarily secures access to the operating system session, preventing unauthorized users from logging into the active OS environment. However, it offers no protection against an attacker with physical access who can bypass the OS login screen entirely. Such an attacker could boot the stolen laptop from an external USB drive containing a live operating system or a password reset utility, thereby gaining direct, unencrypted access to the files on the hard drive.

  • Enable System Restore

    Why it's wrong here

    Enabling System Restore creates periodic snapshots of critical system files, installed applications, and registry settings, allowing the system to revert to a previous stable state in case of software corruption or driver issues. This feature is solely for system recovery and does not encrypt user data, prevent unauthorized access to files, or provide any security against the physical theft of the device. It is entirely unrelated to data protection from physical compromise.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.