220-1102 Security Practice Question
A company security policy requires that all laptops have full-disk encryption. A technician is configuring a laptop that has a TPM chip enabled. Which Windows feature should the technician use to meet this requirement?
⚠ Common exam trap
A common mix-up: candidates confuse EFS with full-disk encryption, not realizing that EFS only provides file-level encryption and does not encrypt the entire volume or integrate with the TPM for pre-boot protection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BitLocker
BitLocker is the correct Windows feature for full-disk encryption on a laptop with a TPM chip. It uses the TPM to securely store encryption keys and can encrypt the entire operating system drive, meeting the company's security policy requirement. EFS only encrypts individual files and folders, not the full disk, and Device Guard is a virtualization-based security feature for application control, not encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EFS
Why it's wrong here
EFS encrypts individual files and folders using a per-user certificate, not the entire volume, so it fails the full-disk encryption requirement. It is tempting because it provides file-level encryption and is built into Windows, making it a correct choice when the policy demands per-user data protection rather than whole-drive coverage.
- ✓
BitLocker
Why this is correct
BitLocker is the correct choice because it is Windows' native full-disk encryption feature, encrypting the entire Windows volume including system files, the pagefile, and hibernation files. It uses AES-based encryption and can integrate with a TPM to securely hold encryption keys and verify the integrity of boot components, ensuring data remains protected even if the laptop is stolen. Because it operates at the volume level and covers the whole drive, it directly fulfills the company's full-disk encryption requirement.
- ✗
Device Guard
Why it's wrong here
Device Guard is a security feature that uses virtualization-based security (VBS) and code integrity policies to ensure that only trusted, signed applications can execute on the system, blocking untrusted software and malware. However, it does not encrypt data at rest; it enforces runtime application control, not storage confidentiality. Even with Device Guard enabled, an attacker who removes the laptop's hard drive and connects it to another machine can still read the raw data because the disk contents remain unencrypted.
- ✗
Credential Manager
Why it's wrong here
Credential Manager is a Windows vault that securely stores usernames and passwords for websites, applications, and network shares, protecting these secrets with DPAPI, but it performs no encryption on the file system or entire volume. Its scope is limited to individual credential blobs, so enabling it cannot satisfy a full-disk encryption policy. In a laptop-theft scenario, Credential Manager leaves the operating system, applications, and user files completely unencrypted and readable.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Windows
Windows is a family of operating systems developed by Microsoft that manages computer hardware and software, providing a graphical user interface for users to interact with their devices.
Key term
BitLocker
BitLocker is a full-disk encryption feature built into Windows that protects data by encrypting the entire drive so that unauthorized users cannot access files without the correct recovery key.
About these practice questions
One of 925 original 220-1102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.