mediumMultiple ChoiceObjective-mapped
220-1102 Practice Question: A small business owner wants to ensure that all…
A small business owner wants to ensure that all company laptops have their hard drives encrypted in case of theft. The laptops run Windows 10 Pro. Which technology should the technician enable to meet this requirement?
⚠ Common exam trap
Candidates often confuse EFS (file-level encryption) with full-disk encryption, or they mistakenly think TPM alone provides encryption, when in fact TPM is merely a key storage and attestation component that requires BitLocker to enable drive encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
BitLocker Drive Encryption
BitLocker Drive Encryption (option C) is the correct technology because it provides full-disk encryption for Windows 10 Pro, ensuring that all data on the laptop's hard drive is encrypted at rest. This protects against data exposure if the device is stolen, as the drive cannot be accessed without the decryption key (e.g., a PIN, USB key, or TPM-based authentication). BitLocker is built into Windows 10 Pro and is specifically designed for whole-drive encryption, meeting the requirement for all company laptops.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EFS (Encrypting File System)
Why it's wrong here
EFS (Encrypting File System) is a feature within Windows that allows users to encrypt individual files and folders on an NTFS file system. While it provides data confidentiality for specific data, it does not encrypt the entire drive or operating system. This means that if a laptop is lost or stolen, an attacker could potentially bypass the operating system and access unencrypted system files or other user data not explicitly protected by EFS, making it insufficient for comprehensive data protection against physical theft.
- ✗
Windows Defender Antivirus
Why it's wrong here
Windows Defender Antivirus is an integrated anti-malware component of Microsoft Windows designed to protect against viruses, spyware, and other malicious software. Its primary function is real-time threat detection, quarantine, and removal, ensuring system integrity and user safety from digital threats. However, it offers no capabilities for encrypting data on a drive to prevent unauthorized access if the physical device is compromised or stolen, thus it is not relevant for data protection in this scenario.
- ✓
BitLocker Drive Encryption
Why this is correct
BitLocker Drive Encryption is a full-disk encryption feature included with Windows Pro and Enterprise editions that encrypts an entire volume, typically the operating system drive. By encrypting all data at rest, BitLocker ensures that even if a laptop is lost or stolen, the data remains inaccessible without the correct decryption key or recovery password. This comprehensive protection is crucial for safeguarding sensitive business information against physical device compromise, directly addressing the need for data protection on lost or stolen laptops.
- ✗
TPM (Trusted Platform Module)
Why it's wrong here
A Trusted Platform Module (TPM) is a specialized microcontroller that secures hardware by integrating cryptographic keys into devices. While a TPM is essential for enhancing the security of full-disk encryption solutions like BitLocker by securely storing and managing the encryption keys, it is not an encryption tool itself. Its role is to provide a secure environment for cryptographic operations and key storage, preventing tampering and unauthorized access to these critical security elements, but it does not perform the data encryption.
Go deeper
Related to this question
Learn chapter
Windows Editions and Features
Key term
Decryption
Decryption is the process of converting encrypted or scrambled data back into its original, readable form using a specific key or method.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
This 220-1202 question is part of Courseiva's 495-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.