220-1102 Security Practice Question
A company's security policy requires that all laptop hard drives be encrypted to protect data in case of theft. Which Windows 10 feature should a technician enable to meet this requirement?
⚠ Common exam trap
Many candidates confuse file-level encryption (EFS) with full-disk encryption (BitLocker), assuming EFS is sufficient for whole-drive protection, but EFS only encrypts selected files and does not secure the operating system or boot volume.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BitLocker Drive Encryption
BitLocker Drive Encryption is the correct feature because it provides full-disk encryption (FDE) for entire volumes, including the operating system drive, using AES encryption algorithms. This meets the security policy requirement to protect all data on a laptop hard drive in case of theft, as it encrypts the entire drive and requires authentication (e.g., TPM, PIN, or USB key) before the system can boot.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
BitLocker Drive Encryption
Why this is correct
BitLocker Drive Encryption is the only option that satisfies the requirement for whole-drive encryption. It encrypts the entire Windows volume, including system files, page files, and user data, using the AES algorithm. BitLocker also integrates with a TPM (Trusted Platform Module) to validate boot integrity and provide pre-boot protection, ensuring data at rest remains unreadable if the drive is removed.
- ✗
Encrypting File System (EFS)
Why it's wrong here
Encrypting File System (EFS) is a Windows feature that encrypts individual files and folders on NTFS volumes, not the entire hard drive. It is user-based and tied to the user's account certificate, meaning only that specific user can decrypt the files. Because EFS leaves system files, temporary files, and other data unencrypted, it does not meet the policy's requirement for full-disk encryption across the entire laptop drive.
- ✗
Secure Boot
Why it's wrong here
Secure Boot is a UEFI-based security feature that ensures only trusted, signed boot loaders and operating system kernels are loaded during the boot process. It protects the boot chain against rootkits and other tampering, but it does not encrypt any data on the hard drive. Since the policy specifically requires encryption of data at rest on laptop hard drives, Secure Boot is irrelevant to that goal.
- ✗
Windows Defender Antivirus
Why it's wrong here
Windows Defender Antivirus is a real-time malware and threat protection solution that detects, quarantines, and removes malicious software. It provides no encryption capabilities whatsoever; it does not scramble data or prevent unauthorized access to a stolen drive. While it is a critical security control, it addresses a different threat model and cannot fulfill the hard-drive encryption requirement.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Encryption Concepts for A+
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
Key term
Security policy
A security policy is a formal set of rules and guidelines that an organization establishes to protect its information assets and technology resources.
About these practice questions
This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.