Courseiva
Security →mediumMultiple Choice

220-1102 Security Practice Question

A company's security policy mandates that all mobile devices be encrypted. A technician enables full-disk encryption on a user's company-issued Android smartphone. Later, the user reports that the phone now prompts for a password before booting and wants to remove this requirement without compromising security. What should the technician explain?

⚠ Common exam trap

Many candidates think the pre-boot password is an optional convenience setting, when in fact it is a mandatory component of full-disk encryption that cannot be removed without disabling encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The pre-boot authentication is a required feature of full-disk encryption and cannot be removed without disabling encryption, which would violate security policy.

Full-disk encryption (FDE) on Android requires a pre-boot password or PIN to decrypt the device at startup. This is a mandatory security feature of FDE, not an optional setting. Disabling the pre-boot authentication would require turning off encryption entirely, which would violate the company's security policy. Therefore, the technician must explain that the password prompt cannot be removed without compromising data protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user can disable the pre-boot password by turning off encryption in the security settings, but this will also remove the data protection.

    Why it's wrong here

    Disabling full-disk encryption to remove the pre-boot password would leave company data unencrypted at rest, directly violating the security policy. In practice, enterprise encryption solutions (e.g., BitLocker, FileVault) require decrypting the entire volume to disable encryption—an operation that is time-consuming and often requires administrative privileges. Doing so solely to eliminate the boot prompt exposes sensitive data to physical theft or unauthorized offline access, which the policy is explicitly designed to prevent.

  • ✓

    The pre-boot authentication is a required feature of full-disk encryption and cannot be removed without disabling encryption, which would violate security policy.

    Why this is correct

    Full-disk encryption inherently requires a decryption key provided at boot. Removing the password would require disabling encryption, which is not allowed per company policy. The user may change the password to a PIN for convenience, but the authentication itself is necessary.

  • ✗

    The user can change the password to a PIN in settings to speed up the boot process while keeping the device encrypted.

    Why it's wrong here

    This option is misleading because switching from a full password to a PIN does not remove the pre-boot authentication requirement—it merely changes the credential format. For example, BitLocker can use a TPM+PIN protector where the TPM validates hardware integrity and the PIN is still required at boot before the encryption key is released. The user's underlying complaint about an extra login step remains, as the device still demands authentication every time it powers on; the PIN simply makes that step quicker, not optional.

  • ✗

    The pre-boot password is only required if the device is lost or stolen; it can be disabled when the device is in a trusted location.

    Why it's wrong here

    Pre-boot authentication is enforced for every boot event regardless of the device's physical location; there is no built-in mechanism that detects 'trusted locations' and bypasses the encryption key release. In theory, a conditional bypass could be implemented via geofencing or network presence, but such checks are spoofable and do not protect data if the device is stolen while outside that trust zone. The security policy mandates uniform protection of data at rest, so any location-based exception would create a serious vulnerability and violate the intent of the mandate.

About these practice questions

One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.