220-1102 Security Practice Question
A company's security policy mandates that all workstations must have full disk encryption. Which Windows feature provides full disk encryption?
⚠ Common exam trap
A common mix-up: candidates confuse EFS (file-level encryption) with full disk encryption, mistakenly thinking EFS can satisfy a policy requiring full disk encryption when it only protects selected files and leaves critical system areas unencrypted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BitLocker
BitLocker Drive Encryption is the native Windows feature that provides full disk encryption (FDE) by encrypting the entire volume, including system files, hibernation files, and page files. It uses AES encryption algorithms (128-bit or 256-bit) and integrates with the Trusted Platform Module (TPM) to ensure the integrity of the boot process, making it the correct answer for a company's FDE mandate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EFS
Why it's wrong here
EFS encrypts files and folders individually using the file owner's certificate/public key, which means data is only protected at the file level and only for files explicitly encrypted by the user. It does not encrypt the entire volume, leaving system files, pagefile.sys, hiberfil.sys, and unencrypted temp files exposed, and it relies on user profile certificates rather than a TPM. For a mandate requiring all workstation data to be encrypted at rest, BitLocker is necessary because EFS cannot provide full-disk coverage.
- ✓
BitLocker
Why this is correct
BitLocker is the Windows native full-disk encryption feature available in Pro, Enterprise, and Education editions; it encrypts the entire operating system volume using AES, including the boot files, system files, pagefile, and any user data residing on that volume. It integrates with the TPM to validate boot integrity and can use a startup PIN or USB key for pre-boot authentication, ensuring data is unreadable if the drive or system is stolen. Since the policy requires all workstations to be fully encrypted, BitLocker directly satisfies this requirement.
- ✗
Defender
Why it's wrong here
Windows Defender (now Microsoft Defender Antivirus) is an endpoint protection platform that provides real-time malware scanning, threat detection, and removal, but it does not perform any encryption of stored data. Its role is to detect and mitigate malicious software, not to protect data confidentiality at rest, so enabling Defender cannot meet a full-disk encryption mandate. Disk encryption and antivirus are complementary security layers, but Defender is the wrong tool for this specific requirement.
- ✗
AppLocker
Why it's wrong here
AppLocker is an application control feature in Windows that enforces allow/deny rules on executables, scripts, Windows Installer files, and DLLs based on path, publisher, or hash, restricting what software can execute in a given context. It is often deployed in security policies to prevent unauthorized applications, but it has no encryption capability and does not protect data at rest on disk. The requirement for workstation encryption must be fulfilled by a full-disk encryption solution like BitLocker, not AppLocker.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
TPM and Secure Boot
Key term
TPM
TPM (Trusted Platform Module) is a dedicated hardware chip on a computer's motherboard that stores cryptographic keys, passwords, and certificates to secure the system against unauthorized access and tampering.
Key term
Integrity
Integrity is the assurance that data has not been altered or tampered with in an unauthorized way, preserving its accuracy and consistency from source to destination.
About these practice questions
Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.