Courseiva
Security →hardMultiple Choice

220-1102 Security Practice Question

A company's security policy requires that all laptops with sensitive data use full disk encryption. Which technology is built into Windows 10 Pro to meet this requirement?

⚠ Common exam trap

It's easy for candidates to confuse BitLocker Drive Encryption with BitLocker To Go, mistakenly thinking both provide full disk encryption for internal drives, when in fact BitLocker To Go is only for removable media.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

BitLocker Drive Encryption

BitLocker Drive Encryption is the built-in Windows 10 Pro feature that provides full disk encryption (FDE) for the entire operating system volume, including system files, hibernation files, and page files. It meets the security policy requirement by encrypting the entire drive at the block level, ensuring that all sensitive data is protected even if the laptop is lost or stolen.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encrypting File System (EFS)

    Why it's wrong here

    EFS encrypts individual files and folders at the file-system level using a per-user certificate, so it does not protect the entire operating system volume. It only works on NTFS volumes and can leave unencrypted copies in system temp files, the paging file, or during file operations. For a company policy requiring full-disk encryption of all laptop drives, EFS is insufficient because it does not cover system files, boot records, or data outside the user's selected folders.

  • ✓

    BitLocker Drive Encryption

    Why this is correct

    BitLocker Drive Encryption provides full-volume encryption for the entire operating system volume, protecting all system files, boot files, and user data at rest. It uses AES encryption and can be unlocked via a TPM, a PIN, a USB startup key, or a combination, ensuring that the laptop's data is unreadable when the device is off. This is the built-in Windows tool that meets the requirement of full-disk encryption on supported Windows 10 Pro or Enterprise editions.

  • ✗

    BitLocker To Go

    Why it's wrong here

    BitLocker To Go is the BitLocker feature used exclusively for encrypting removable drives such as USB flash drives and external hard drives, not the internal laptop hard drive. It does not provide full-disk encryption for the computer's boot volume or operating system partition. Since the company's policy mandates that all laptops have full-disk encryption on their internal storage, BitLocker To Go does not address the internal drive and cannot satisfy the requirement.

  • ✗

    Trusted Platform Module (TPM)

    Why it's wrong here

    TPM is a dedicated hardware security chip that generates and stores cryptographic keys used for encryption, but it is not itself an encryption mechanism. While a TPM strengthens BitLocker by providing secure key storage and integrity attestation, the actual disk encryption is performed by the BitLocker software. Selecting TPM would confuse a hardware component with the policy's required full-disk encryption solution, which is BitLocker Drive Encryption.

About these practice questions

Courseiva writes every 220-1102 question from scratch — 925 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.