220-1102 Security Practice Question
A company policy requires that all data on laptops be encrypted so that if a laptop is stolen, the data cannot be read even if the hard drive is removed. Which Windows 10 feature provides this?
⚠ Common exam trap
Many exam-takers confuse file-level encryption (EFS) with full-disk encryption (BitLocker), assuming any encryption feature meets the 'data cannot be read even if the hard drive is removed' requirement, but EFS leaves the OS and unencrypted files exposed, failing the policy's strict offline protection condition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BitLocker
BitLocker is the correct answer because it provides full-disk encryption (FDE) for Windows 10 laptops, ensuring that all data on the drive, including the operating system, user files, and temporary files, is encrypted at rest. When the hard drive is removed and attached to another system, the data remains inaccessible without the correct recovery key or TPM authentication, meeting the policy requirement that data cannot be read even after physical theft of the drive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
BitLocker
Why this is correct
BitLocker is a full-disk encryption feature built into Windows Pro and Enterprise editions. It encrypts the entire volume, including system files, user data, and the pagefile, using AES encryption, and can be tied to a TPM chip for hardware-based key protection. Even if the drive is physically removed and mounted in another machine, the data remains unreadable without the correct recovery key or authentication. This satisfies the policy's requirement that all data on laptops be encrypted.
- ✗
EFS
Why it's wrong here
EFS (Encrypting File System) is a Windows feature that provides encryption at the file and folder level, not full-disk encryption. It uses the user's profile and a cryptographic key to decrypt files transparently, but system files, temporary files, and any data outside the encrypted folder remain unencrypted. Because the requirement mandates that all data on laptops be encrypted, EFS is insufficient as it leaves large parts of the drive exposed.
- ✗
User Account Control
Why it's wrong here
User Account Control (UAC) is a security mechanism that prompts for administrator approval when a program attempts to make system-level changes. It helps prevent unauthorized modifications to the OS, but it does not perform any encryption of data on the disk. UAC simply gates privilege elevation; it has no mechanism to encrypt files, folders, or volumes, so it cannot meet the encryption policy.
- ✗
Windows Defender
Why it's wrong here
Windows Defender is a built-in antivirus and antimalware solution that scans for and removes malicious software. While it protects against threats like ransomware and malware that could steal or damage data, it does not encrypt data at all. Without any encryption capability, Windows Defender cannot convert the laptop's data into ciphertext, making it completely unsuitable for enforcing an encryption policy.
Go deeper
Related to this question
Learn chapter
Encryption Concepts for A+
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
Key term
Recovery key
A recovery key is a unique code or physical device used to regain access to an encrypted system or account when the primary authentication method, such as a password or biometric, is lost or unavailable.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on 220-1102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company wants to ensure that sensitive data on laptops is protected in case the laptop is lost or stolen. Which technology provides full-disk encryption for Windows 10?
medium- ✓ A.BitLocker
- B.EFS
- C.TPM
- D.Secure Boot
Why A: BitLocker is the correct technology because it provides full-disk encryption (FDE) for Windows 10, encrypting the entire operating system volume and all data on the drive. It uses the AES encryption algorithm (typically 128-bit or 256-bit) and integrates with the Trusted Platform Module (TPM) to ensure the integrity of the boot process, protecting data even if the laptop is lost or stolen.
Variation 2. A company wants to protect the data on its fleet of laptops. The security policy requires that if a laptop is stolen, the data on the internal hard drive must be unreadable even if the drive is removed and placed into another computer. Which technology, available on Windows 10 Pro, meets this requirement?
medium- ✓ A.BitLocker Drive Encryption
- B.Encrypting File System (EFS)
- C.Secure Boot
- D.TPM (Trusted Platform Module)
Why A: BitLocker Drive Encryption is the correct answer because it provides full-disk encryption at the sector level, ensuring that all data on the internal hard drive is encrypted with AES (typically 128-bit or 256-bit). If the drive is removed and placed into another computer, the encrypted data remains unreadable without the recovery key or TPM authentication, directly meeting the policy requirement for stolen laptops.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.