Courseiva
easyMultiple Choice

220-1102 Practice Question: A company policy requires that all sensitive data…

A company policy requires that all sensitive data stored on laptops must be unreadable if the device is lost or stolen. A technician is tasked with implementing a solution that works transparently for users. Which approach should they take?

⚠ Common exam trap

CompTIA often tests the distinction between access control (passwords, screen locks) and data-at-rest encryption; the trap here is confusing a screen lock or BIOS password with actual encryption, which does not protect data if the drive is physically removed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable BitLocker drive encryption on each laptop.

BitLocker drive encryption provides full-disk encryption that operates transparently to the user, automatically encrypting all data on the system drive. If the laptop is lost or stolen, the data remains unreadable without the decryption key, satisfying the policy requirement without requiring user intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable BitLocker drive encryption on each laptop.

    Why this is correct

    BitLocker encrypts the entire volume with AES, rendering data unreadable without the recovery key or TPM-bound credentials, satisfying the policy requirement for lost or stolen laptops. Encryption and decryption occur transparently during normal use, so users notice no workflow change. BitLocker also supports Microsoft Entra ID escrow for key recovery.

  • ✗

    Set a BIOS password on each laptop.

    Why it's wrong here

    A BIOS password only gates firmware access before boot; the storage device can be removed and read on another machine, leaving sensitive data readable. It tempts as a pre-boot barrier, but it protects hardware configuration, not data at rest, which requires full-disk encryption.

  • ✗

    Implement a folder-level password policy using EFS.

    Why it's wrong here

    EFS encrypts files but leaves them readable to anyone logged into the Windows account, so a stolen laptop's data remains accessible; folder-level passwords are not a real EFS construct. It tempts because EFS does encrypt data at rest, and would suit protecting specific folders on a shared, physically secured machine.

  • ✗

    Configure a screensaver password with a 1-minute timeout.

    Why it's wrong here

    A screensaver password only locks the interactive session; the disk remains fully readable if the drive is removed or the OS bypassed, so data is not unreadable at rest. It tempts as a cheap endpoint hardening step, but full-disk encryption such as BitLocker is the transparent control that satisfies the policy.

About these practice questions

Courseiva writes every 220-1202 question from scratch — 687 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.